Dacls is a cross-platform remote access trojan associated with the Lazarus Group, including Windows, Linux, and macOS variants. First observed around 2018, it is notable as an early publicly exposed Lazarus malware family for Linux and has also been referred to in some reporting as MATA. The malware uses a shared command-and-control protocol across platforms and is designed to provide full remote control of compromised systems.
Dacls employs layered command-and-control communications using TLS followed by RC4-encrypted tasking. It stores encrypted configuration data locally and can receive updated configuration from its operators. The Linux variant runs as a background daemon and the macOS variant uses comparable configuration and plugin architecture. Reported functionality includes command execution, file management, process management, host information collection, heartbeat signaling, connectivity testing, proxying traffic between command infrastructure and other hosts, and network scanning. Dacls can enumerate running and parent processes, terminate processes, create daemonized processes, and exfiltrate collected data or command output to operator-controlled infrastructure.
The malware demonstrates multiple defense-evasion and persistence techniques. On Linux and macOS, payloads have been hidden using dot-prefixed names to reduce visibility in standard file listings and Finder. The macOS Mach-O variant has been disguised as a benign-looking interface resource, and macOS persistence has been established through LaunchAgents, with some variants attempting LaunchDaemon persistence when executed with elevated privileges. The macOS variant has also been observed delivered inside a trojanized application, indicating social-engineering-based installation in at least some cases.
Dacls has been linked to Lazarus through infrastructure overlap, code and protocol similarities, and relationships to other Lazarus-attributed tooling. Reporting has also suggested possible deployment via exploitation of Atlassian Confluence CVE-2019-3396 in some Linux intrusions. The malware’s cross-platform design and modular remote administration capabilities make it suitable for long-term post-compromise access against enterprise systems, including servers and user endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
我们在疑似被感染的下载服务器 http://www.areac-agr.com/cms/wp-content/uploads/2015/12/ 上找到了一系列样本,其中包括Win32.Dacls和Linux.Dacls,开源程序Socat,以及Confluence CVE-2019-3396 Payload。所以,我们推测Lazarus Group曾经利用CVE-2019-3396 N-day漏洞传播Dacls Bot程序。 | 所以,我们会详细披露它的一些技术特征,并根据它的文件名和硬编码字符串特征将它命名为Dacls。Dacls是一款新型的远程控制软件,包括Windows和Linux版本并共用C2协议,我们将它们分别命名为Win32.Dacls和Linux.Dacls。
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dacls - RAT tied to Lazarus APT group reported by 360 Netlab. Researchers found both ELF and PE versions of this malware. This is Lazarus’s first exposed Linux malware.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
如果Linux进程中的PID对应的 /proc/<pid>/task 目录存在,Bot样本会收集如下进程信息... Uid //用户ID Gid //用户组ID
当Bot收到该指令后会按照3种规则随机生成公网IP地址并尝试连接8291端口,如果连接成功就向log server回传扫描结果。
The C2 protocol utilizes TLS and RC4 double-layer encryption. After establishing a TLS connection, Dacls beacons to the C2 server and then exchanges a key for the RC4 encryption.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The Reverse P2P plug-in is actually a C2 Connection Proxy, it directs network traffic between bots and C2 to avoid direct connections to their infrastructure. This is a common used technique by the Lazarus Group.
Reverse P2P插件实际上是一种C2连接代理(Connection Proxy),它通过下发控制命令可以将指定的C2数据完整的转发到指定IP端口。
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT associated with Lazarus, with both ELF and PE variants; described as Lazarus's first exposed Linux malware.
Cross-platform remote access trojan used by Lazarus Group. It uses a C2 protocol with TLS and RC4 double-layer encryption, beacons to command-and-control servers, exchanges an RC4 key, and then receives commands such as host information collection, heartbeat, and configuration download.
Remote access trojan that collects data on running and parent processes.
Dacls is a cross-platform remote access trojan (RAT) attributed to the Lazarus Group (North Korea). It provides full command and control over infected systems, supporting command execution, file management, process management, network scanning, and C2 proxying. The macOS variant is distributed via trojanized applications and persists via launch agents or daemons.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.