Malware.View on attack.mitre.org
DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally since at least summer 2020. DRATzarus shares similarities with Bankshot, which was used by Lazarus Group in 2017 to target the Turkish financial sector.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
DRATzarus can collect information from a compromised host. |
| T1018 Remote System Discovery |
DRATzarus can search for other machines connected to compromised host and attempt to map the network. |
| T1027 Obfuscated Files or Information |
DRATzarus can be partly encrypted with XOR. |
| T1027.002 Software Packing |
DRATzarus's dropper can be packed with UPX. |
| T1033 System Owner/User Discovery |
DRATzarus can obtain a list of users from an infected machine. |
| T1036.005 Match Legitimate Resource Name or Location |
DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`. |
| T1057 Process Discovery |
DRATzarus can enumerate and examine running processes to determine if a debugger is present. |
| T1071.001 Web Protocols |
DRATzarus can use HTTP or HTTPS for C2 communications. |
| T1105 Ingress Tool Transfer |
DRATzarus can deploy additional tools onto an infected machine. |
| T1106 Native API |
DRATzarus can use various API calls to see if it is running in a sandbox. |
| T1124 System Time Discovery |
DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time. |
| T1497.003 Time Based Checks |
DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade |
| T1622 Debugger Evasion |
DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.