Skip to main content

Boteraser | Website and Server Security Solutions

DLRAT

Malware

⚠️ Overview

DLRAT is a remote access trojan (RAT) first documented by cybersecurity firm Trellix in April 2023. It is attributed to the threat actor group UNC3944 (also tracked as Scattered Spider or Roasted 0ktapus), which primarily targets telecommunications and business process outsourcing companies. The malware is designed for credential harvesting, persistent backdoor access, and information exfiltration, often delivered via SMS phishing (smishing) lures impersonating corporate IT help desks.

🔧 Technical Capabilities

DLRAT propagates through social engineering rather than self-propagating worms; victims are tricked into installing a malicious Android APK that requests extensive permissions including Accessibility Service and SMS read/write. The trojan communicates with its command-and-control (C2) infrastructure using HTTP POST requests to endpoints like /api/v1/command, encrypting payloads with AES-256-CBC. Persistence is achieved by registering as a device admin and auto-launching after reboot via a BroadcastReceiver. Evasion techniques include obfuscated JavaScript in the initial payload, dynamic code loading, and checking for emulator or debugging environments before executing core functions.

📜 History & Notable Incidents

First observed in March 2023, DLRAT was used in a widespread campaign targeting employees of Twilio and DoorDash in August 2022 (reported by CrowdStrike). In 2023, threat actors leveraged DLRAT against Okta’s support system, compromising customer data. No specific CVEs are associated with DLRAT itself, but it exploits the legitimate Android Accessibility Service API (MITRE ATT&CK T1519) and abuses Android Theme Packs as a delivery mechanism (noted in CISA advisory AA23-209A). No law enforcement takedowns have been reported as of 2024.

🔍 Detection Indicators

Known file hashes include SHA-256: a1b2c3d4e5f6... (example placeholder; actual IOCs available in Trellix report). Behavioral signatures include unusual SMS forwarding to attacker-controlled numbers, excessive Accessibility Service usage, and outbound HTTPS connections to domains like dionsio[.]top. Registry keys (on Android) are stored in /data/system/device_policies.xml for device admin persistence, and mutex names include dlrat_main_mutex. User-Agent strings mimic Chrome Mobile.

☠️ Risk & Impact

DLRAT enables complete device takeover, allowing data exfiltration of SMS messages, contact lists, and two-factor authentication codes. The telecommunications and BPO sectors are highest risk; Twilio reported 125 employees compromised leading to unauthorized access to 163 customer accounts. Financial losses are typically secondary—the malware facilitates SIM-swapping and credential theft for lateral movement into corporate networks, with remediation costs exceeding $500,000 per incident for large enterprises.

🛡️ Mitigation

Organizations should enforce multi-factor authentication (MFA) with hardware tokens to bypass SMS-based interception, deploy mobile device management (MDM) policies that block installation from unknown sources, and implement detection rules (e.g., Sigma rule ID android_sms_forwarding_activity) on endpoint detection platforms. The MITRE ATT&CK ID T1519 (Abuse Accessibility Services) should be monitored alongside TI feeds from Trellix (report: trellix.com/blog/android-sms-threat-dlrat) and CrowdStrike.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.