Dacls

MITRE ATT&CK: S0497 View on attack.mitre.org

Aliases: Dacls

First seen
2019-12-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
macos, linux, windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-15 16:39:22
Profile updated
2026-07-07 14:35:24

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Dacls (S0497). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample TinkaOTP.dmg 2026-06-15 1

Detection coverage

  • 2 YARA rules
  • 178 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Launch Agent (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Launch Daemon (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Masquerading (attack-pattern)

Used by threat actors

Detection rules

  • DEADBITS_Dacls_Trojan_Windows (yara-rule)
  • DEADBITS_Dacls_Trojan_Linux (yara-rule)

Reports & references

  • sentinelone.com — Four Distinct Families Of Lazarus Malware Target Apples Macos Platform (report)
  • Trend Micro — New Macos Dacls Rat Backdoor Show Lazarus Multi Platform Attack Capability (report)
  • MITRE ATT&CK — S0497 (report)

External references