Dtrack is a Windows remote access trojan associated with the North Korean Lazarus Group and with activity tracked as WASSONITE. It supports espionage and post-compromise operations through process execution, file upload and download, and collection of information from infected systems. Its victimology includes financial institutions, research centers, manufacturing organizations, and electric-generation and nuclear-energy entities. Dtrack was identified at India's Kudankulam Nuclear Power Plant.
Dtrack can enumerate running processes, collect host IP addresses and network configuration, inspect network connections, and gather browser history and file listings across local, removable, and network volumes. A variant used at Kudankulam packaged collected information into password-protected archives and copied them to an internal network share using hard-coded credentials. Dtrack can establish persistence through a Windows service, remove its persistence, and delete itself.
Its droppers use encrypted payloads, runtime decryption, in-memory loading, and process hollowing to execute the implant within legitimate Windows processes. Samples have also masqueraded as legitimate applications, including OllyDbg, 7-Zip, and FileZilla. A variant identified in April 2020 could communicate with Fujitsu Systemwalker management software. Dtrack is distinct from ATMDtrack, an ATM-focused malware family that collects payment-card data and has been observed dropping Dtrack.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
approximately ten hours prior to deploying Maui... the group deployed a variant of the well-known DTrack malware... Once this malware is spawned, it executes an embedded shellcode, loading a final Windows in-memory payload... responsible for collecting victim information and sending it to the remote host.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dtrack is a RAT (Remote Administration Tool) allegedly written by the North Korean Lazarus group. Recently the Dtrack malware was found in the Indian nuclear power plant “Kudankulam Nuclear Power Plant” (KNPP).
While Kaspersky discovered the use of Dtrack and Maui, we've observed the use of VSingle, YamaBot and MagicRAT.
On April 17, 2020, Dragos identified a variant of DTrack malware with technical overlaps to previously observed samples associated with WASSONITE.
DTrack is a malware attributed to Lazarus / APT38. Recent DTrack samples found on critical infrastructures like nuclear power plants...
"DTrack (also known as VinoSiren and Preft). DTrack was used in 2019 to target a nuclear power facility in India..."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
$ str_reg_move = / move \/ y %s \\ [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \\ C \$\\ Windows \\ Temp \\ MpLogs \\ / | $ str_reg_use = / net use \\ [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \\ C \$ \/ delete /
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-linked backdoor/RAT supporting file transfer, keylogging, screenshot capture, and lateral movement; newer variants use process hollowing (e.g., explorer.exe).
Custom North Korea-linked malware used for lateral movement and persistence in compromised environments.
Custom malware used to maintain access and steal information during intrusions; described here as an infostealer used by North Korean actors during initial access and lateral movement preceding a Play ransomware incident.
Custom Lazarus malware family used for persistence and remote access within victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.