North Korean hacker group Lazarus using updated DTrack backdoor to breach numerous business & govt. entities across Europe & Latin America…

Continue reading
The infamous North Korean threat group Lazarus, possibly behind the new wave of attacks involving the updated version of DTrack evident across organizations in Europe and Latin America. According to the Kaspersky telemetry report DTrack found to be active in Germany, Brazil, Italy, Mexico, Switzerland, Saudi Arabia, Turkey, the United States and India. Government research institutions, policy institutes, chemical manufacturers, IT service providers, communications providers, utility service providers, and the education sector are among the top targeted industries.
It is a modular backdoor featuring a keylogger, a screenshot snapper, a browser history retriever, a running processes snooper, an IP address and network connection information snatcher, and more.
The backdoor was first discovered in 2019 used in a wide range of attacks including Kudankulam nuclear power plant. Not only does it spy on its victim, but it may also steal data, modify files, run commands to perform file operations, fetch additional payloads and start processes on the infected devices.
Over the course of time, DTrack has not changed drastically, besides the updated version of the backdoor doesn't feature much functionalities as compared to the previous samples. However, it is worth mentioning that DTrack conceals itself within an executable that appears to be a normally running program with multiple phases of decryption before the malware payload is executed & deployed far more widely.
Following successful decryption of the final payload (a DLL), process hollowing is used to inject the malicious code into the _"explorer.exe"_ process, running directly from memory.
Previously DTrack examples only provided cryptic strings for the libraries that needed to be loaded. API hashing is used to load the appropriate libraries and functions in newer versions. Another minor adjustment is the usage of just three C2 servers instead of six. In all other respects, the payload's functionality is unaltered.
DTrack backdoor still considered to be an important asset for Lazarus group as they continues to leverage in various campaigns translating it to be a reason for minimal modification since 2019.
`1A74C8D8B74CA2411C1D3D22373A6769` `67F4DAD1A94ED8A47283C2C0C05A7594`

Backdoor.Daxin, the kernel-mode rootkit Symantec once called the most advanced tool ever tied to a China-linked espionage actor, has been found running again