Dtrack

MITRE ATT&CK: S0567 View on attack.mitre.org

Aliases: Preft, TroyRAT, Dtrack

Malware type
spyware, rat
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2026-06-20 14:20:30
Profile updated
2026-07-07 12:53:55

Targeted industries: energy-and-utilities financial-services government-and-public-sector

Targeted regions: country_code:in

Context

Dtrack is spyware that was discovered in 2019 and has been used against Indian financial institutions, research facilities, and the Kudankulam Nuclear Power Plant. Dtrack shares similarities with the DarkSeoul campaign, which was attributed to Lazarus Group.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Dtrack (S0567). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample sub_fe51590db6f8.bin 2026-06-20 2
file sample 2026-06-04_881fd027093e6898d60385c9bb46bdd2_amadey_darkgate_dtrack_elex_emote... 2026-06-06 1

Detection coverage

  • 5 YARA rules
  • 358 Sigma rules

Malware & tools used

  • Data from Local System (attack-pattern)
  • Local Data Staging (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Hijack Execution Flow (attack-pattern)
  • Keylogging (attack-pattern)
  • Boot or Logon Autostart Execution (attack-pattern)
  • Windows Service (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Valid Accounts (attack-pattern)
  • File Deletion (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Query Registry (attack-pattern)
  • Process Hollowing (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Shared Modules (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_MAL_APT_NK_Andariel_Nopineapple_Dtrack_Unpacked (yara-rule)
  • SIGNATURE_BASE_MAL_APT_NK_Andariel_Dtrack_Unpacked (yara-rule)
  • SIGNATURE_BASE_MAL_APT_NK_WIN_Dtrack_Auto (yara-rule)
  • SIGNATURE_BASE_APT_MAL_DTRACK_Oct19_1 (yara-rule)
  • MALPEDIA_Win_Dtrack_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • dragos.com — Wassonite (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • Kaspersky — 99204 (report)
  • brandefense.io — Lazarus Apt Group Apt38 (report)
  • blog.macnica.net — Dtrack (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dtrack (report)
  • marcoramilli.com — Is Lazarus Apt38 Targeting Critical Infrastructures (report)
  • Broadcom/Symantec — Stonefly North Korea Espionage (report)
  • Kaspersky — 93338 (report)
  • cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
  • Kaspersky — 107063 (report)
  • cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
  • cyberbit.com — Dtrack Apt Malware Found In Nuclear Power Plant (report)
  • labs.withsecure.com — Withsecure Lazarus No Pineapple Threat Intelligence Report 2023 (report)
  • media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
  • Kaspersky — 107798 (report)
  • Palo Alto Unit 42 — North Korean Threat Group Play Ransomware (report)
  • github.com — Dtrack Lazarus Group.Md (report)
  • twitter.com — 1399369260577681426 (report)
  • MITRE ATT&CK — S0567 (report)
  • usa.kaspersky.com — 2019 Dtrack Previously Unknown Spy Tool Hits Financial Institutions And Research Centers (report)
  • zdnet.com — Confirmed North Korean Malware Found On Indian Nuclear Plants Network (report)

External references