DTrack activity targeting Europe and Latin America

2022-11-15 • Kaspersky •

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

Thumbnail for DTrack activity targeting Europe and Latin America

Kaspersky reported that Lazarus continued using the DTrack backdoor three years after its 2019 discovery, with telemetry showing activity in Europe, Latin America, the Middle East, Asia, and the United States. DTrack supports file upload, download, execution, and deletion, and its toolset has included a keylogger, screenshot module, and system information collector that can support lateral movement and data theft. Recent samples used multi-stage unpacking and decryption, modified RC4/RC5/RC6-like algorithms, API hashing, process hollowing into explorer.exe, and a reduced set of three C2 servers. The reported victimology included education, chemical manufacturing, government research and policy institutes, IT services, utilities, and telecommunications, showing Lazarus continued to adapt an older backdoor for varied financial and strategic operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3fe624c33790b409421f4fa2bb8abfd… 2022-11-15 2023-02-10
HASH ba8f9e7afe5f78494c111971c39a891… 2022-11-15 2023-02-10
DOMAIN purplebear.com 2022-11-15 2022-11-15
IPv4 52.128.23.153 2022-11-15 2022-11-15
IPv4 64.190.63.111 2022-11-15 2022-11-15
IPv4 58.158.177.102 2022-11-15 2022-11-15
DOMAIN purewatertokyo.com 2021-03-22 2022-11-15
DOMAIN salmonrabbit.com 2021-03-22 2022-11-15
DOMAIN pinkgoat.com 2021-03-22 2022-11-15

Related Actors

Related Reports

« Back