DRATzarus

S0694

Malware.View on attack.mitre.org

About this malware

DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally since at least summer 2020. DRATzarus shares similarities with Bankshot, which was used by Lazarus Group in 2017 to target the Turkish financial sector.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1005
Data from Local System

DRATzarus can collect information from a compromised host.

T1018
Remote System Discovery

DRATzarus can search for other machines connected to compromised host and attempt to map the network.

T1027
Obfuscated Files or Information

DRATzarus can be partly encrypted with XOR.

T1027.002
Software Packing

DRATzarus's dropper can be packed with UPX.

T1033
System Owner/User Discovery

DRATzarus can obtain a list of users from an infected machine.

T1036.005
Match Legitimate Resource Name or Location

DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`.

T1057
Process Discovery

DRATzarus can enumerate and examine running processes to determine if a debugger is present.

T1071.001
Web Protocols

DRATzarus can use HTTP or HTTPS for C2 communications.

T1105
Ingress Tool Transfer

DRATzarus can deploy additional tools onto an infected machine.

T1106
Native API

DRATzarus can use various API calls to see if it is running in a sandbox.

T1124
System Time Discovery

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time.

T1497.003
Time Based Checks

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade
detection.

T1622
Debugger Evasion

DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim.

Groups that use it0

None recorded.

Campaigns1

References1

  1. ClearSky Lazarus Aug 2020 Open source
    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.