Dtrack is a RAT (Remote Administration Tool) allegedly written by the North Korean Lazarus group. Recently the Dtrack malware was found in the Indian nuclear power plant “Kudankulam Nuclear Power Plant” (KNPP).
Dtrack
DTrack is a Lazarus Group backdoor and remote administration tool used in espionage and financially motivated intrusions.
Dtrack
Family profile
DTrack is a Lazarus Group backdoor and remote administration tool used in espionage and financially motivated intrusions. First publicly identified in 2019, it has remained in active use in later campaigns and has been associated with North Korean operations targeting financial environments, critical infrastructure, research organizations, utilities, telecommunications, IT service providers, chemical manufacturing, and other sectors. Reported victimology includes activity in India as well as broader targeting across Europe, Latin America, the Middle East, and North America.
DTrack is designed for post-compromise control, reconnaissance, and data theft. Documented capabilities include collecting host and network information, enumerating running processes, gathering browser history, listing files across local and network-accessible storage, uploading and downloading files, executing commands or processes, and deleting itself or removing persistence for cleanup. Some observed DTrack toolsets have also included keylogging and screenshot capture modules, and the malware has been used to support lateral movement inside victim environments.
Recent DTrack variants use multi-stage unpacking and layered shellcode to hinder analysis. Observed samples decrypt embedded payload stages using modified cryptographic routines and resolve APIs dynamically, with newer variants using API hashing. Multiple samples have used process hollowing to inject the final payload into legitimate Windows processes, including explorer.exe, and some droppers have masqueraded as legitimate software to reduce suspicion. DTrack has also been observed hiding inside replicas of benign applications and using patched legitimate executables as loaders.
Operational reporting has linked DTrack to targeted intrusions against critical infrastructure, including a case involving an Indian nuclear power facility in which the malware was used after an apparent prior foothold had already been established. In that operation, the malware collected system, network, and file inventory data and staged the results for transfer. Separate reporting has tied DTrack activity to the WASSONITE cluster targeting manufacturing, electric generation, nuclear energy, and research entities, and later variants were noted to interact with Fujitsu Systemwalker software in enterprise and data-center environments.
Overall, DTrack is best characterized as a mature Lazarus espionage backdoor focused on reconnaissance, collection, and sustained post-exploitation access, with strong emphasis on stealth through staged decryption, masquerading, and process hollowing.
Capabilities
- Defense Evasion
- Exfiltration
- Keylogging
- Lateral Movement
- Persistence
- Post Exploitation
- Process Injection
- Reconnaissance
Samples
Recent samples
3 sandbox samples in the Derp library, newest 3 shown
Reported operators
Threat actors
5 named in public reportingWhile Kaspersky discovered the use of Dtrack and Maui, we've observed the use of VSingle, YamaBot and MagicRAT.
On April 17, 2020, Dragos identified a variant of DTrack malware with technical overlaps to previously observed samples associated with WASSONITE.
DTrack is a malware attributed to Lazarus / APT38. Recent DTrack samples found on critical infrastructures like nuclear power plants...
"DTrack (also known as VinoSiren and Preft). DTrack was used in 2019 to target a nuclear power facility in India..."
Exploited software
Vulnerabilities linked to Dtrack
1 CVEsMITRE ATT&CK
Dtrack in ATT&CK
47 distinct techniquesTechniques
47 techniquesReporting
Research mentioning Dtrack
Bluenoroff (APT38) Live Infrastructure Hunting - Darkatlas
North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.
Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor
Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.
Cutting-off the Command-and-Control Infrastructure of CollectorGoomba | Threat Bulletin | VMRay
A look at the ATM/PoS malware landscape from 2017-2019 | Securelist
Kaspersky reported that ATM and point-of-sale malware activity rose sharply in 2018 and remained high in 2019, with detections concentrated in Russia, Brazil, Iran, Vietnam, India, the United States, and several European countries. Russia consistently recorded the highest number of affected devices, underscoring the global scale of attacks targeting payment infrastructure. The report linked the sustained threat to outdated software, unpatched vulnerabilities, weak physical security, and the operational limits of vendor-managed ATM environments. It identified active malware families including ATMJackpot, WinPot, Ice5, ATMTest, Peralta, ATMWizX, ATMDtrack, ATMgot, ATMqotX, and ATMJaDi, which support cash-out schemes, card-data theft, and anti-forensic functions, while noting that older malware continues to be reused and that a malware-as-a-service trend is emerging from Latin America.