Thief in the Dark: Lazarus Uses Dtrack RAT Tool to Steal Massive Medical Data
2020-12-18 • Threat Book •
ThreatBook describes Lazarus using Dtrack RAT in an intrusion that exposed large volumes of medical files and affected servers or PCs across multiple countries and regions. The operators compromised public-facing servers and reused them as Dtrack C2 infrastructure, a pattern the report links to Lazarus scan, brute force, and exploit activity. The client decrypts configuration with RC4, collects host and registration details, checks in over HTTP, and supports file transfer, remote shell, and encrypted command results. Server-side PHP components on compromised hosts stored victim check-ins, issued commands, and held tools and stolen data, giving defenders C2 URLs and related IOCs for detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 145.232.235.222 | 2020-12-18 | 2022-08-09 |
| HASH | f5b338d6bca36d47ee04d93d08c57861 | 2020-12-18 | 2020-12-18 |
| URL | http://www.bwaprzemysl.pl/formu… | 2020-12-18 | 2020-12-18 |
| IPv4 | 36.99.136.129 | 2020-12-18 | 2020-12-18 |
| IPv4 | 46.14.68.202 | 2020-12-18 | 2020-12-18 |
| IPv4 | 68.183.78.131 | 2020-12-18 | 2020-12-18 |
| IPv4 | 36.99.136.136 | 2020-12-18 | 2020-12-18 |