DTrack is a Lazarus Group backdoor and remote administration tool used in espionage and financially motivated intrusions. First publicly identified in 2019, it has remained in active use in later campaigns and has been associated with North Korean operations targeting financial environments, critical infrastructure, research organizations, utilities, telecommunications, IT service providers, chemical manufacturing, and other sectors. Reported victimology includes activity in India as well as broader targeting across Europe, Latin America, the Middle East, and North America.
DTrack is designed for post-compromise control, reconnaissance, and data theft. Documented capabilities include collecting host and network information, enumerating running processes, gathering browser history, listing files across local and network-accessible storage, uploading and downloading files, executing commands or processes, and deleting itself or removing persistence for cleanup. Some observed DTrack toolsets have also included keylogging and screenshot capture modules, and the malware has been used to support lateral movement inside victim environments.
Recent DTrack variants use multi-stage unpacking and layered shellcode to hinder analysis. Observed samples decrypt embedded payload stages using modified cryptographic routines and resolve APIs dynamically, with newer variants using API hashing. Multiple samples have used process hollowing to inject the final payload into legitimate Windows processes, including explorer.exe, and some droppers have masqueraded as legitimate software to reduce suspicion. DTrack has also been observed hiding inside replicas of benign applications and using patched legitimate executables as loaders.
Operational reporting has linked DTrack to targeted intrusions against critical infrastructure, including a case involving an Indian nuclear power facility in which the malware was used after an apparent prior foothold had already been established. In that operation, the malware collected system, network, and file inventory data and staged the results for transfer. Separate reporting has tied DTrack activity to the WASSONITE cluster targeting manufacturing, electric generation, nuclear energy, and research entities, and later variants were noted to interact with Fujitsu Systemwalker software in enterprise and data-center environments.
Overall, DTrack is best characterized as a mature Lazarus espionage backdoor focused on reconnaissance, collection, and sustained post-exploitation access, with strong emphasis on stealth through staged decryption, masquerading, and process hollowing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
approximately ten hours prior to deploying Maui... the group deployed a variant of the well-known DTrack malware... Once this malware is spawned, it executes an embedded shellcode, loading a final Windows in-memory payload... responsible for collecting victim information and sending it to the remote host.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dtrack is a RAT (Remote Administration Tool) allegedly written by the North Korean Lazarus group. Recently the Dtrack malware was found in the Indian nuclear power plant “Kudankulam Nuclear Power Plant” (KNPP).
While Kaspersky discovered the use of Dtrack and Maui, we've observed the use of VSingle, YamaBot and MagicRAT.
On April 17, 2020, Dragos identified a variant of DTrack malware with technical overlaps to previously observed samples associated with WASSONITE.
DTrack is a malware attributed to Lazarus / APT38. Recent DTrack samples found on critical infrastructures like nuclear power plants...
"DTrack (also known as VinoSiren and Preft). DTrack was used in 2019 to target a nuclear power facility in India..."
31 distinct techniques documented for this family, organized by ATT&CK tactic.
WASSONITE targets manufacturing, electric generation, nuclear energy, and research entities in India, and likely South Korea and Japan. The group’s operations rely on DTrack malware, credential capture tools, and system tools for lateral movement.
The dropper creates a suspended Microsoft process from a predefined list, in this case napstat.exe... It injects code into it by allocating memory, writing into it, modifying the thread context structure and then resuming the thread execution.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The second stage payload consists of heavily obfuscated shellcode... The encryption method used by the second layer differs for each sample. So far, we have spotted modified versions of RC4, RC5 and RC6 algorithms.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The dropper creates a suspended Microsoft process from a predefined list, in this case napstat.exe... It injects code into it by allocating memory, writing into it, modifying the thread context structure and then resuming the thread execution.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The variant of Dtrack that attacked this power planet included hardcoded credentials for KNPP’s internal network, suggesting that it was a targeted attack.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The information used for creating the identifier includes registry values (RegisteredOwner, RegisteredOrganization, InstallDate), computer name and adapter information (MAC addresses).
ATMDtruck also appeared in the fall of 2018... It collects enough information from the credit cards inputted into the infected ATM that it can actually clone them.
“C:\Windows\system32\cmd.exe” /c netstat -naop tcp > ...\netstat.res
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
$ str_reg_move = / move \/ y %s \\ [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \\ C \$\\ Windows \\ Temp \\ MpLogs \\ / | $ str_reg_use = / net use \\ [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \. [ 0 - 9 ] { 1,3 } \\ C \$ \/ delete /
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Among those downloaded and executed files already spotted in the standard DTrack toolset there is a keylogger
This file is then copied to a network share at \\10.38.1.35\C$\Windows\Temp\MpLogs\
Another small change is that three C2 servers are used instead of six.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-linked backdoor/RAT supporting file transfer, keylogging, screenshot capture, and lateral movement; newer variants use process hollowing (e.g., explorer.exe).
Custom North Korea-linked malware used for lateral movement and persistence in compromised environments.
Custom malware used to maintain access and steal information during intrusions; described here as an infostealer used by North Korean actors during initial access and lateral movement preceding a Play ransomware incident.
Custom Lazarus malware family used for persistence and remote access within victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.