Hello! My name is Dtrack

2019-09-23 • Kaspersky •

https://securelist.com/my-name-is-dtrack/93338/

Thumbnail for Hello! My name is Dtrack

Kaspersky’s Dtrack analysis links the RAT family to Lazarus through code similarities with older malware and activity against India’s financial sector and research centers. The investigation began with ATMDtrack banking malware targeting Indian ATMs and expanded to more than 180 Dtrack samples uncovered through shared code sequences. Droppers stored encrypted payloads in PE overlays, decrypted them at runtime, and used process hollowing to run spying components under system process names. The report details a Lazarus-associated espionage toolset focused on payload concealment, process hollowing, and data collection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe51590db6f835a3a210eba178d78d5… 2019-09-23 2020-03-09
HASH 9d9571b93218f9a635cfeb67b3b31e2… 2019-09-23 2019-09-23
HASH 58fef66f346fe3ed320e22640ab9970… 2019-09-23 2019-09-23

Related Reports

« Back