• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
north korean hackers targeting europe and latin america with updated

North Korean Hackers Targeting Europe and Latin America with Updated DTrack Backdoor

You are here: Home / General Cyber Security News / North Korean Hackers Targeting Europe and Latin America with Updated DTrack Backdoor
November 17, 2022

Hackers tied to the North Korean governing administration have been noticed working with an updated variation of a backdoor recognized as Dtrack focusing on a large vary of industries in Germany, Brazil, India, Italy, Mexico, Switzerland, Saudi Arabia, Turkey and the U.S.

“Dtrack makes it possible for criminals to add, download, commence or delete documents on the sufferer host,” Kaspersky scientists Konstantin Zykov and Jornt van der Wiel reported in a report.

The victimology designs point out an growth to Europe and Latin The united states. Sectors qualified by the malware are schooling, chemical production, governmental investigation centers and coverage institutes, IT support suppliers, utility suppliers, and telecommunication corporations.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Dtrack, also named Valefor and Preft, is the handiwork of Andariel, a subgroup of the Lazarus nation-state menace actor that’s publicly tracked by the broader cybersecurity neighborhood making use of the monikers Procedure Troy, Silent Chollima, and Stonefly.

Identified in September 2019, the malware has been earlier deployed in a cyber attack aimed at a nuclear electrical power plant in India, with extra recent intrusions using Dtrack as element of Maui ransomware attacks.

Industrial cybersecurity firm Dragos attributed the nuclear facility attack to a risk actor it calls WASSONITE, pointing out the use of Dtrack for distant obtain to the compromised network.

The most current modifications observed by Kaspersky relate to how the implant conceals its presence in a seemingly genuine system (“NvContainer.exe” or “XColorHexagonCtrlTest.exe”) and the use of a few levels of encryption and obfuscation designed to make assessment additional challenging.

The last payload, on decryption, is subsequently injected into the Windows File Explorer system (“explorer.exe”) applying a strategy known as method hollowing. Chief among the modules downloaded by Dtrack is a keylogger as well as resources to capture screenshots and gather system information.

“The Dtrack backdoor proceeds to be applied actively by the Lazarus team,” the scientists concluded. “Modifications in the way the malware is packed demonstrate that Lazarus nonetheless sees Dtrack as an vital asset.”

Found this post intriguing? Follow THN on Facebook, Twitter  and LinkedIn to go through more exclusive material we submit.


Some elements of this short article are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Android Privacy Sandbox Beta to Roll Out By Early 2023
Next Post: Iranian Hackers Compromised a U.S. Federal Agency’s Network Using Log4Shell Exploit iranian hackers compromised a u.s. federal agency's network using log4shell»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.