Malware.View on attack.mitre.org
Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Dacls can encrypt its configuration file with AES CBC. |
| T1036 Masquerading |
The Dacls Mach-O binary has been disguised as a .nib file. |
| T1057 Process Discovery |
Dacls can collect data on running and parent processes. |
| T1071.001 Web Protocols |
Dacls can use HTTPS in C2 communications. |
| T1083 File and Directory Discovery |
Dacls can scan directories on a compromised host. |
| T1105 Ingress Tool Transfer |
Dacls can download its payload from a C2 server. |
| T1543.001 Launch Agent |
Dacls can establish persistence via a LaunchAgent. |
| T1543.004 Launch Daemon |
Dacls can establish persistence via a Launch Daemon. |
| T1564.001 Hidden Files and Directories |
Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.