The Lazarus Group used its DTrack malware in sustained espionage operations against financial institutions, research centers, utilities, government entities, telecommunications providers, IT services, and chemical manufacturers, with victim telemetry extending from Asia into Europe and Latin America. Reporting tied DTrack to intrusions at organizations including a nuclear power facility in India, where investigators said the malware was deployed as a second-stage tool after initial access had already been obtained, underscoring its role in targeted reconnaissance and data theft rather than broad disruptive activity.
Researchers described DTrack as a modular backdoor and remote administration tool that evolved over time while preserving core spying functions. Samples were observed collecting browser history, IP and network configuration data, running process lists, connection status to internal systems, and file inventories, then archiving and copying results to remote shares. Later variants added multi-stage unpacking, layered shellcode, modified RC4/RC5/RC6-based decryption, API hashing, and process hollowing into explorer.exe, while public detection content, including YARA rules and associated SHA-256 hashes, was released to help defenders identify known DTrack artifacts and infrastructure patterns.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Securelist reported continued Lazarus use of DTrack, describing newer multi-stage variants and expanded victim telemetry across Europe and Latin America.
A GitHub repository entry was updated with a YARA rule named "dtrack_2020" and associated SHA-256 hashes for detecting DTrack malware linked to Lazarus.
Cyberbit published analysis stating that a DTrack variant was found in India's Kudankulam Nuclear Power Plant and that the sample contained hardcoded internal network credentials, indicating a targeted intrusion.
Kaspersky publicly reported DTrack as a previously unknown Lazarus-linked spy tool and said it had hit financial institutions and research centers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcegithub.com
Open sourcecyberbit.com
Open sourceusa.kaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.