Researchers have discovered that hackers from North Korea have created a new malware that is placed on systems and aims to record and steal data from cards that users into the infected machine. have inserted 
Kaspersky researchers have published a report describing the malware. The malware is called ATMDtrack and was detected in Indian banking networks . It was first discovered in late summer 2018.
Hackers have evolved the malware and are also targeting Indian research centers. The new, more powerful version is called DTrack and is mainly used for spying and stealing personal data. It has many features that are usually found in remote access trojans (RATs).
Kaspersky researchers reported that both versions of the malware closely resembled the malware used in “Operation DarkSeoul,” a series of attacks on targets in South Korea in 2013.
These attacks came from the Lazarus, a group that engages in electronic espionage and takes orders from the government North Korean

The Lazarus Group and two other North Korean hacking groups were indicted ten days ago by the US. The groups were accused of carrying out attacks on banks, ATMs, sites gambling cryptocurrency exchanges. The hackers' goal was to steal money and raise funds for the country's military equipment.
The discovery of the ATMDtrack malware appears to confirm the US Treasury Department's decision to impose sanctions.
Dtrack is one of the latest creations of the Lazarus group. Although it first appeared in August 2018, hackers have used it again now.
The capabilities of Dtrack, which have now been observed, are the following:
- Keylogging
- Browser history recovery
- Collection of IP addresses, network information
- Recording of processes being executed
- File recording
Researchers do not know whether DTrack was developed from ATMDTrack or whether ATMDTrack was developed from Dtrack.
