DRATzarus is a Lazarus Group malware family associated with the North Korean Operation Dream Job intrusion set and later reporting on TraderTraitor-linked activity. It is used as part of targeted espionage operations and appears in a broader Lazarus toolchain alongside malware such as Sumarta, DBLL Dropper, and Torisma. Available reporting supports that it operates on Windows systems and is deployed with a dedicated dropper that may be packed with UPX for defense evasion.
DRATzarus performs host and network reconnaissance on compromised systems. Documented behaviors include collecting information from the infected host, obtaining a list of local users, inspecting system time through Windows API calls, and searching for other machines connected to the compromised host in order to map the surrounding network. It also incorporates anti-analysis features, including debugger detection via IsDebuggerPresent, sandbox checks using multiple API-based environment tests, and timing-based evasion using GetTickCount and GetSystemTimeAsFileTime. Under certain conditions it can enter a sleep state remotely to reduce exposure during analysis or detection.
The malware has been observed in Lazarus operations that relied heavily on social engineering and recruiter-themed lures, particularly Operation Dream Job, in which victims were approached with fictitious job opportunities. In that campaign, Lazarus used malicious documents, template injection, and related droppers to deliver custom malware families including DRATzarus. The malware’s role is consistent with post-compromise reconnaissance and operational support inside victim enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64... During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
"DRATzarus can use various API calls to see if it is running in a sandbox"; "EvilBunny ... checks to see if the malware is running in a sandbox"
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
"DRATzarus can use various API calls to see if it is running in a sandbox"; "EvilBunny ... checks to see if the malware is running in a sandbox"
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named remote access trojan referenced in TraderTraitor-related reporting.
Remote access trojan capable of obtaining a list of users from an infected machine.
A remote access trojan that searches for connected machines and maps the victim network.
Custom Lazarus remote access trojan used in Operation Dream Job; the content also notes DRATzarus was encrypted with XOR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.