HomeSecurityLazarus Group Attacks Linux Systems via Dacls Trojan

Lazarus Group Attacks Linux Systems via Dacls Trojan

TrojanThe Lazarus (APT) is constantly evolving and increasing attacks , developing a new Trojan that targets systems Linux.

The Lazarus Group is said to have ties to the North Korean government and has been linked to several global cyberattacks. Some of its most notable attacks include the spread of the WannaCry ransomware, the theft of $80 million from a Bangladeshi bank, and a new campaign targeting financial institutions around the world.

Some researchers claim that these hackers have also used Trickbot (used by many government hacking groups) to gain access to infected systems.

The Lazarus group has purchased many tools from other hackers in the past. However, it also creates its own weapons, such as the new Remote Access Trojan (RAT), which was discovered by researchers at Netlab 360.

The security firm said the trojan, called Dacls, first appeared in May and while it was detected by more than 20 companies offering antivirus solutions, it is still considered “unknown.”

Researchers analyzed a sample of the malware and found it to be a “fully functional RAT program for Windows and Linux,” likely associated with this group.

Lazarus Group Attacks Linux Systems via Dacls Trojan

A domain associated with the malware, thevagabondsatchel.com, is a further indication of the Lazarus group's involvement, as the site had previously been used by the APT to store malware.

Researchers believe that CVE-2019-3396, a remote code execution flaw affecting the Atlassian Confluence server macro version 6.6.12 (and older), is being used to infect systems and deploy Dacls.

The RAT, which varies depending on the operating system it targets, shares its command-and-control (C2) protocol. Dacls is a modular malware and uses TLS and RC4 encryption when communicating with its C2, as well as AES encryption to protect configuration files.

When a vulnerable Linux system is detected, the malware runs in the background and checks for updates.

The Trojan is capable of performing various functions such as stealing, deleting, executing files, scanning directories, downloading other payloads, terminating processes, uploading data , and more.

As we said above, the trojan spreads through a known vulnerability and there is already a patch available, so IT administrators should update their Confluence setups to stay safe.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS