Dtrack
Description
Dtrack is a Remote Administration Tool (RAT) developed by the Lazarus group. Its core functionality includes operations to upload a file to the victim’s computer, download a file from the victim’s computer, dump disk volume data, persistence and more.
A variant of Dtrack was found on Kudankulam Nuclear Power Plant (KNPP) which was used for a targeted attack.
Names
Name |
---|
Dtrack |
TroyRAT |
Preft |
Category
Malware
Type
- Backdoor
- Info stealer
- Exfiltration
Information
- https://securelist.com/my-name-is-dtrack/93338/
- https://securelist.com/dtrack-targeting-europe-latin-america/107798/
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
5a3e9d46-de22-4cd7-af31-cc7ea1079471
Last Card Change
2023-11-30