Thief in the Dark: Lazarus Uses Dtrack RAT Tool to Steal Massive Medical Data

2020-12-18 Threat Book

https://threatbook.io/blog/Thief-in-the-Dark:-Lazarus-Uses-Dtrack-RAT-Tool-to-Steal-Massive-Medical-Data

ThreatBook describes Lazarus using Dtrack RAT in an intrusion that exposed large volumes of medical files and affected servers or PCs across multiple countries and regions. The operators compromised public-facing servers and reused them as Dtrack C2 infrastructure, a pattern the report links to Lazarus scan, brute force, and exploit activity. The client decrypts configuration with RC4, collects host and registration details, checks in over HTTP, and supports file transfer, remote shell, and encrypted command results. Server-side PHP components on compromised hosts stored victim check-ins, issued commands, and held tools and stolen data, giving defenders C2 URLs and related IOCs for detection.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 145.232.235.222 2020-12-18 2022-08-09
HASH f5b338d6bca36d47ee04d93d08c57861 2020-12-18 2020-12-18
URL http://www.bwaprzemysl.pl/formu… 2020-12-18 2020-12-18
IPv4 36.99.136.129 2020-12-18 2020-12-18
IPv4 46.14.68.202 2020-12-18 2020-12-18
IPv4 68.183.78.131 2020-12-18 2020-12-18
IPv4 36.99.136.136 2020-12-18 2020-12-18

Related Actors

Related Reports

« Back