DRATzarus

MITRE ATT&CK: S0694 View on attack.mitre.org

Aliases: ThreatNeedle, ThreatNeedleTea, DRATzarus

First seen
2020-07-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:24:02

Targeted industries: defense-and-aerospace financial-services

Context

DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally since at least summer 2020. DRATzarus shares similarities with Bankshot, which was used by Lazarus Group in 2017 to target the Turkish financial sector.

Detection coverage

  • 1 YARA rules
  • 281 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Software Packing (attack-pattern)
  • Process Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Used by threat actors

  • Operation Dream Job (campaign)

Detection rules

  • MALPEDIA_Win_Dratzarus_Auto (yara-rule)

Reports & references

  • vblocalhost.com — Vb2021 Park (report)
  • virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
  • brandefense.io — Lazarus Apt Group Apt38 (report)
  • wiz.io — North Korean Tradertraitor Crypto Heist (report)
  • Kaspersky — 116326 (report)
  • blog.nsfocus.net — Stumbzarus Apt Lazarus (report)
  • blog.google — New Campaign Targeting Security Researchers (report)
  • gendigital.com — Dprk Kimsuky Lazarus Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dratzarus (report)
  • clearskysec.com — Dream Job Campaign (report)
  • MITRE ATT&CK — S0694 (report)

External references