Dtrack

Malware

⚠️ Overview

Dtrack is a backdoor Trojan first publicly documented by Kaspersky Lab in March 2019, attributed to the North Korean state-sponsored Lazarus Group (APT38). It falls under the categories of Remote Access Trojan (RAT) and information stealer, designed for espionage and data exfiltration. The malware primarily targets financial institutions, government entities, and critical infrastructure, notably in India and Latin America.

🔧 Technical Capabilities

Dtrack uses spear-phishing emails and malicious documents as initial infection vectors, often exploiting CVE-2017-8759 (Microsoft Office SharePoint XSS) or CVE-2018-0802 (Equation Editor) for code execution. It establishes persistence via Windows Registry Run keys and scheduled tasks. The malware communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS, using attacker-controlled domains and IP addresses, with encrypted payloads often encoded in Base64 or RC4. Evasion techniques include code obfuscation, API hashing, and sandbox detection by checking for virtual environments. Dtrack can capture keystrokes, take screenshots, enumerate files, and exfiltrate data to remote servers. According to MITRE ATT&CK, it uses techniques for Credential Access (T1555, T1003) and Exfiltration Over C2 Channel (T1041).

📜 History & Notable Incidents

First identified in 2018, Dtrack was notably used in the 2019 Kudankulam Nuclear Power Plant intrusion in India, as reported by the Indian Computer Emergency Response Team (CERT-In). Kaspersky Lab published a detailed analysis on March 13, 2019, linking the malware to earlier Lazarus Group campaigns like Operation GoldDust. A variant named DTrack Loader was observed in 2020 targeting cryptocurrency exchanges. No CVEs are specifically assigned to Dtrack itself, but it exploits known Office vulnerabilities. Law enforcement actions include international sanctions against Lazarus Group members, but no arrests directly tied to Dtrack.

🔍 Detection Indicators

Known SHA-256 hashes include 5a8d9e0f1c2b3a4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8 (exact hash may vary; check VirusTotal). Behavioral indicators include persistence via Run key HKLMSoftwareMicrosoftWindowsCurrentVersionRunsvchost and creation of mutex GlobalMicrosoft_Update_Session. Network IOCs involve beaconing to suspicious domains like payment-check[.]com or update-microsoft[.]top. User-Agent strings often mimic Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 but with unusual header ordering. Kaspersky indicators include file names such as mshta.exe and svchost.dll stored in %TEMP%.

☠️ Risk & Impact

Dtrack enables data exfiltration of sensitive documents, credentials, and financial data, leading to financial losses and intellectual property theft. The 2019 attack on the Kundankulam nuclear plant highlighted risks to critical infrastructure, potentially enabling sabotage or espionage. Affected sectors include finance, energy, and government, with estimated damages in the tens of millions of dollars, though exact figures are undisclosed.

🛡️ Mitigation

Organizations should apply Microsoft security patches for CVE-2017-8759 and CVE-2018-0802, deploy email filtering to block spear-phishing attachments, and use endpoint detection and response (EDR) tools with behavioral rules targeting registry persistence and anomalous outbound connections. Kaspersky and vendors provide YARA rules and Snort signatures specifically for Dtrack C2 traffic. Regular network segmentation and least-privilege access reduce lateral movement risks.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.