#DLRAT
Malware/Tool
2023-12-11 • Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
DLRAT is a DLang-based remote access trojan used by Lazarus Group during Operation Blacksmith. Cisco Talos distinguished it from NineRAT, another DLang RAT in the campaign that uses Telegram bots and channels for command-and-control, and from the DLang downloader BottomLoader. The operation exploited internet-facing enterprise infrastructure vulnerable to CVE-2021-44228, also known as Log4Shell, and targeted manufacturing, agricultural, and physical security organizations globally. The observed tactics and procedures overlapped with those associated with Onyx Sleet, also known as PLUTIONIUM or Andariel, which is widely regarded as a subgroup under the Lazarus umbrella.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days