#NineRAT

Malware/Tool

2023-12-11 • Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang

NineRAT is a remote access trojan written in DLang and operated through Telegram bots and channels for command-and-control communications. Lazarus used it during Operation Blacksmith alongside the non-Telegram DLRAT and the BottomLoader downloader. The campaign opportunistically compromised globally exposed enterprise infrastructure through n-day exploitation, including Log4Shell, and affected manufacturing, agricultural, and physical-security organizations. Its use reflects Lazarus adoption of uncommon development technologies and overlaps with activity associated with the Andariel subgroup.

Tagged Reports

« Back