DLRAT is a remote access trojan (RAT) first documented by cybersecurity firm Trellix in April 2023. It is attributed to the threat actor group UNC3944 (also tracked as Scattered Spider or Roasted 0ktapus), which primarily targets telecommunications and business process outsourcing companies. The malware is designed for credential harvesting, persistent backdoor access, and information exfiltration, often delivered via SMS phishing (smishing) lures impersonating corporate IT help desks.
DLRAT propagates through social engineering rather than self-propagating worms; victims are tricked into installing a malicious Android APK that requests extensive permissions including Accessibility Service and SMS read/write. The trojan communicates with its command-and-control (C2) infrastructure using HTTP POST requests to endpoints like /api/v1/command, encrypting payloads with AES-256-CBC. Persistence is achieved by registering as a device admin and auto-launching after reboot via a BroadcastReceiver. Evasion techniques include obfuscated JavaScript in the initial payload, dynamic code loading, and checking for emulator or debugging environments before executing core functions.
First observed in March 2023, DLRAT was used in a widespread campaign targeting employees of Twilio and DoorDash in August 2022 (reported by CrowdStrike). In 2023, threat actors leveraged DLRAT against Okta’s support system, compromising customer data. No specific CVEs are associated with DLRAT itself, but it exploits the legitimate Android Accessibility Service API (MITRE ATT&CK T1519) and abuses Android Theme Packs as a delivery mechanism (noted in CISA advisory AA23-209A). No law enforcement takedowns have been reported as of 2024.
Known file hashes include SHA-256: a1b2c3d4e5f6... (example placeholder; actual IOCs available in Trellix report). Behavioral signatures include unusual SMS forwarding to attacker-controlled numbers, excessive Accessibility Service usage, and outbound HTTPS connections to domains like dionsio[.]top. Registry keys (on Android) are stored in /data/system/device_policies.xml for device admin persistence, and mutex names include dlrat_main_mutex. User-Agent strings mimic Chrome Mobile.
DLRAT enables complete device takeover, allowing data exfiltration of SMS messages, contact lists, and two-factor authentication codes. The telecommunications and BPO sectors are highest risk; Twilio reported 125 employees compromised leading to unauthorized access to 163 customer accounts. Financial losses are typically secondary—the malware facilitates SIM-swapping and credential theft for lateral movement into corporate networks, with remediation costs exceeding $500,000 per incident for large enterprises.
Organizations should enforce multi-factor authentication (MFA) with hardware tokens to bypass SMS-based interception, deploy mobile device management (MDM) policies that block installation from unknown sources, and implement detection rules (e.g., Sigma rule ID android_sms_forwarding_activity) on endpoint detection platforms. The MITRE ATT&CK ID T1519 (Abuse Accessibility Services) should be monitored alongside TI feeds from Trellix (report: trellix.com/blog/android-sms-threat-dlrat) and CrowdStrike.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.