DLang is a remote access trojan (RAT)/implant associated with the North Korean state-sponsored threat group Andariel, also tracked as Onyx Sleet, formerly PLUTONIUM, and also referenced as DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. It is listed in a joint FBI-led Cybersecurity Advisory (AA24-207A) as one of multiple Andariel-developed RATs used in the group’s cyber espionage and ransomware operations. The advisory attributes this activity to the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau.
Within the advisory, DLang is identified as part of Andariel’s broader malware ecosystem used after initial compromise. The group commonly gains access by exploiting public-facing web servers and known vulnerabilities, including CVE-2021-44228 (Log4Shell), then deploying web shells, establishing persistence via Scheduled Tasks, stealing credentials with tools such as Mimikatz, and moving laterally with SMB, RDP, and built-in system tools. The advisory states Andariel uses custom implants and RATs, including DLang, to support capabilities such as arbitrary command execution, keylogging, screenshots, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure. Each implant typically uses a designated C2 node to maintain access.
DLang is associated with campaigns targeting defense, aerospace, nuclear, and engineering organizations for theft of sensitive military and technical information and intellectual property, with additional targeting of medical and energy sectors. The advisory assesses these operations support Pyongyang’s military and nuclear programs, and notes that Andariel has also funded espionage through ransomware attacks against U.S. healthcare entities. No DLang-specific indicators of compromise are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ DLang
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.