Dtrack

S0567

Malware.View on attack.mitre.org

About this malware

Dtrack is spyware that was discovered in 2019 and has been used against Indian financial institutions, research facilities, and the Kudankulam Nuclear Power Plant. Dtrack shares similarities with the DarkSeoul campaign, which was attributed to Lazarus Group.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1005
Data from Local System

Dtrack can collect a variety of information from victim machines.

T1012
Query Registry

Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values.

T1016
System Network Configuration Discovery

Dtrack can collect the host's IP addresses using the ipconfig command.

T1027.009
Embedded Payloads

Dtrack has used a dropper that embeds an encrypted payload as extra data.

T1036.005
Match Legitimate Resource Name or Location

One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.

T1049
System Network Connections Discovery

Dtrack can collect network and active connection information.

T1055.012
Process Hollowing

Dtrack has used process hollowing shellcode to target a predefined list of processes from %SYSTEM32%.

T1056.001
Keylogging

Dtrack’s dropper contains a keylogging executable.

T1057
Process Discovery

Dtrack’s dropper can list all running processes.

T1059.003
Windows Command Shell

Dtrack has used cmd.exe to add a persistent service.

T1070.004
File Deletion

Dtrack can remove its persistence and delete itself.

T1074.001
Local Data Staging

Dtrack can save collected data to disk, different file formats, and network shares.

T1078
Valid Accounts

Dtrack used hard-coded credentials to gain access to a network share.

T1082
System Information Discovery

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.

T1083
File and Directory Discovery

Dtrack can list files on available disk volumes.

View all 23 procedure examples

Groups that use it1

Campaigns0

None recorded.

References5

  1. CyberBit Dtrack Open source
    Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.
  2. Dragos WASSONITE Open source
    Dragos. (n.d.). WASSONITE. Retrieved January 20, 2021.
  3. Kaspersky Dtrack Open source
    Kaspersky Global Research and Analysis Team. (2019, September 23). DTrack: previously unknown spy-tool by Lazarus hits financial institutions and research centers. Retrieved January 20, 2021.
  4. Securelist Dtrack Open source
    Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021.
  5. ZDNet Dtrack Open source
    Catalin Cimpanu. (2019, October 30). Confirmed: North Korean malware found on Indian nuclear plant's network. Retrieved January 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.