Dacls

S0497

Malware.View on attack.mitre.org

About this malware

Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Dacls can encrypt its configuration file with AES CBC.

T1036
Masquerading

The Dacls Mach-O binary has been disguised as a .nib file.

T1057
Process Discovery

Dacls can collect data on running and parent processes.

T1071.001
Web Protocols

Dacls can use HTTPS in C2 communications.

T1083
File and Directory Discovery

Dacls can scan directories on a compromised host.

T1105
Ingress Tool Transfer

Dacls can download its payload from a C2 server.

T1543.001
Launch Agent

Dacls can establish persistence via a LaunchAgent.

T1543.004
Launch Daemon

Dacls can establish persistence via a Launch Daemon.

T1564.001
Hidden Files and Directories

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

Groups that use it1

Campaigns0

None recorded.

References2

  1. SentinelOne Lazarus macOS July 2020 Open source
    Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.
  2. TrendMicro macOS Dacls May 2020 Open source
    Mabutas, G. (2020, May 11). New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability. Retrieved August 10, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.