North Korean hackers (Lazarus) are using a new version of the DTrack backdoor to target organizations in Europe and Latin America.

DTrack backdoor that can be used to monitor keystrokes (keylogging), take screenshots, retrieve browser history, monitor running processes, and collect IP address and network connection information.
See also: Billbug group targets government services in Asian countries
In addition to the above (which are more related to espionage), DTrack also has the ability to execute commands, steal files and data, execute additional payloads , and run processes on compromised devices.
Although this new version of the malware does not offer many functional or code changes compared to existing samples, it is being used more in attacks.
Distribution
According to a report published by Kaspersky, DTrack activity was detected in Germany, Brazil, India, Italy, Mexico, Switzerland, Saudi Arabia, Turkey, and the United States.
Targeted sectors include government research centers, policy institutes, chemical manufacturers, IT service providers, telecommunications providers, utility providers, and education.
In recent weeks, Kaspersky has observed that DTrack is being distributed using filenames that are usually associated with legitimate executable programs.
For example, one of the malware is disguised as “NvContainer.exe”, which NVidia uses for one of its own files.
See also: Bug on Apple devices causes Safari to crash when certain letters are typed

“DTrack hides inside an executable file that looks like a legitimate program, and there are multiple decryption stages before the malware payload is launched,” the report states.
Kaspersky said that the DTrack backdoor is installed on compromised networks using stolen credentials or by exploiting servers exposed to the Internet, as observed in previous campaigns.
The only notable changes from previous variants of DTrack are that it now uses API hashing to load libraries and functions, and that the number of C2 servers has been reduced from six to three.
Some of the C2 servers discovered by Kaspersky are: “pinkgoat[.]com”, “purewatertokyo[.]com”, “purplebear[.]com”, and “salmonrabbit[.]com.”
DTrack backdoor: Which hackers use it?
Kaspersky believes that DTrack is linked to the North Korean hacking group Lazarus, which appears to use it whenever it wants to gain financial gain. Lazarus has been responsible for many devastating cyberattacks over the past decade. The group is believed to be state-funded and has ties to the North Korean military. In recent years, Lazarus has shifted its focus from traditional hacking to cryptocurrency theft and is believed to be behind a series of attacks on crypto exchanges.
See also: 42,000 websites tricked users into thinking they were legitimate
In August 2022, the same researchers had linked the backdoor to hackers “Andariel” also associated with North Korea. This is the same group that deployed the Maui ransomware on corporate networks in America and South Korea.
Dragos linked DTrack to a North Korean threat group, “Wassonite,” in February 2020. Wassonite had previously attacked nuclear power and oil and gas facilities.
Source: www.bleepingcomputer.com
