Dacls (Windows)

Aliases: MATA

Malware type
rat
Profile updated
2026-07-07 13:03:43

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:kr country_code:jp

Context

According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely. Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.

Reports & references

  • Kaspersky — 97937 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • Kaspersky — 97757 (report)
  • Kaspersky — 97746 (report)
  • sygnia.co — Mata Framework (report)
  • blog.netlab.360.com — Dacls The Dual Platform Rat (report)
  • vblocalhost.com — Vb2021 Park (report)
  • blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dacls (report)
  • media.kasperskycontenthub.com — Updated Mata Attacks Eastern Europe Full Report Eng (report)
  • ptsecurity.com — Dark River You Can T See Them But They Re There (report)
  • blogs.vmware.com — Threat Analysis Active C2 Discovery Using Protocol Emulation Part4 Dacls Aka Mata (report)
  • malwareandstuff.com — Peb Where Magic Is Stored (report)

External references