Dacls, also known as MATA, is a modular, cross-platform remote access trojan used by the North Korea-linked Lazarus Group. It targets Windows, Linux, and macOS, with artifacts observed as early as April 2018. Its Windows and Linux variants share a command-and-control protocol, while the macOS variant closely resembles their architecture and configuration format.
Dacls provides remote command execution, file management, process management, host reconnaissance, network connectivity testing, network scanning, and command-and-control traffic proxying. Its process-management functionality can enumerate running and parent processes, terminate processes, and create background processes. File-management functionality supports reading, writing, deleting, searching for, and downloading files. The Linux variant includes a module that scans public IP space for exposed network services and uploads scan results or command output through HTTP POST requests. Its reverse-proxy functionality forwards traffic between command-and-control infrastructure and specified hosts.
The Linux implant runs as a background daemon and incorporates its plugin functionality directly into the executable; the Windows variant can retrieve plugin modules remotely. Dacls encrypts stored configuration data with AES and uses layered TLS and RC4 encryption for command-and-control communications.
The macOS variant has been distributed through a trojanized TinkaOTP two-factor authentication application. It attempts persistence through LaunchAgents or, when running with root privileges, LaunchDaemons. Its defense-evasion techniques include hidden, dot-prefixed payload names, disguising a Mach-O executable as an application resource, dynamically constructing strings, and basic obfuscation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
我们在疑似被感染的下载服务器 http://www.areac-agr.com/cms/wp-content/uploads/2015/12/ 上找到了一系列样本,其中包括Win32.Dacls和Linux.Dacls,开源程序Socat,以及Confluence CVE-2019-3396 Payload。所以,我们推测Lazarus Group曾经利用CVE-2019-3396 N-day漏洞传播Dacls Bot程序。 | 所以,我们会详细披露它的一些技术特征,并根据它的文件名和硬编码字符串特征将它命名为Dacls。Dacls是一款新型的远程控制软件,包括Windows和Linux版本并共用C2协议,我们将它们分别命名为Win32.Dacls和Linux.Dacls。
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dacls - RAT tied to Lazarus APT group reported by 360 Netlab. Researchers found both ELF and PE versions of this malware. This is Lazarus’s first exposed Linux malware.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
如果Linux进程中的PID对应的 /proc/<pid>/task 目录存在,Bot样本会收集如下进程信息... Uid //用户ID Gid //用户组ID
当Bot收到该指令后会按照3种规则随机生成公网IP地址并尝试连接8291端口,如果连接成功就向log server回传扫描结果。
The C2 protocol utilizes TLS and RC4 double-layer encryption. After establishing a TLS connection, Dacls beacons to the C2 server and then exchanges a key for the RC4 encryption.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The Reverse P2P plug-in is actually a C2 Connection Proxy, it directs network traffic between bots and C2 to avoid direct connections to their infrastructure. This is a common used technique by the Lazarus Group.
Reverse P2P插件实际上是一种C2连接代理(Connection Proxy),它通过下发控制命令可以将指定的C2数据完整的转发到指定IP端口。
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT associated with Lazarus, with both ELF and PE variants; described as Lazarus's first exposed Linux malware.
Cross-platform remote access trojan used by Lazarus Group. It uses a C2 protocol with TLS and RC4 double-layer encryption, beacons to command-and-control servers, exchanges an RC4 key, and then receives commands such as host information collection, heartbeat, and configuration download.
Its Mach-O binary has been disguised using a .nib extension.
Remote access trojan that collects data on running and parent processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.