Dtrack
MITRE ATT&CK: S0567 View on attack.mitre.org
Aliases: Preft, TroyRAT, Dtrack
- Malware type
- spyware, rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-06-20 14:20:30
- Profile updated
- 2026-07-07 12:53:55
Targeted industries: energy-and-utilities financial-services government-and-public-sector
Targeted regions: country_code:in
Context
Dtrack is spyware that was discovered in 2019 and has been used against Indian financial institutions, research facilities, and the Kudankulam Nuclear Power Plant. Dtrack shares similarities with the DarkSeoul campaign, which was attributed to Lazarus Group.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Dtrack (S0567). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | sub_fe51590db6f8.bin | 2026-06-20 | 2 |
| file sample | 2026-06-04_881fd027093e6898d60385c9bb46bdd2_amadey_darkgate_dtrack_elex_emote... | 2026-06-06 | 1 |
Detection coverage
- 5 YARA rules
- 358 Sigma rules
Malware & tools used
- Data from Local System (attack-pattern)
- Local Data Staging (attack-pattern)
- System Information Discovery (attack-pattern)
- Hijack Execution Flow (attack-pattern)
- Keylogging (attack-pattern)
- Boot or Logon Autostart Execution (attack-pattern)
- Windows Service (attack-pattern)
- Windows Command Shell (attack-pattern)
- Valid Accounts (attack-pattern)
- File Deletion (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Embedded Payloads (attack-pattern)
- Query Registry (attack-pattern)
- Process Hollowing (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Shared Modules (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Detection rules
- SIGNATURE_BASE_MAL_APT_NK_Andariel_Nopineapple_Dtrack_Unpacked (yara-rule)
- SIGNATURE_BASE_MAL_APT_NK_Andariel_Dtrack_Unpacked (yara-rule)
- SIGNATURE_BASE_MAL_APT_NK_WIN_Dtrack_Auto (yara-rule)
- SIGNATURE_BASE_APT_MAL_DTRACK_Oct19_1 (yara-rule)
- MALPEDIA_Win_Dtrack_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- dragos.com — Wassonite (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- Kaspersky — 99204 (report)
- brandefense.io — Lazarus Apt Group Apt38 (report)
- blog.macnica.net — Dtrack (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dtrack (report)
- marcoramilli.com — Is Lazarus Apt38 Targeting Critical Infrastructures (report)
- Broadcom/Symantec — Stonefly North Korea Espionage (report)
- Kaspersky — 93338 (report)
- cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
- Kaspersky — 107063 (report)
- cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
- cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
- labs.withsecure.com — Withsecure Lazarus No Pineapple Threat Intelligence Report 2023 (report)
- media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
- Kaspersky — 107798 (report)
- Palo Alto Unit 42 — North Korean Threat Group Play Ransomware (report)
- github.com — Dtrack Lazarus Group.Md (report)
- twitter.com — 1399369260577681426 (report)
- MITRE ATT&CK — S0567 (report)
- usa.kaspersky.com — 2019 Dtrack Previously Unknown Spy Tool Hits Financial Institutions And Research Centers (report)
- zdnet.com — Confirmed North Korean Malware Found On Indian Nuclear Plants Network (report)