Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Dacls

Dacls

TLP:CLEAR
Family

AI Analysis

· 16 hours ago

Executive Summary

Dacls is a cross‐platform RAT that gives Lazarus Group persistent remote access to Windows, Linux, and macOS machines. It supports covert command execution, keylogging, screenshot capture, and data exfiltration over encrypted channels. The malware’s modular design enables attackers to add or update capabilities as needed.

Enhanced Description

Dacls is a sophisticated cross‐platform remote access trojan (RAT) that has been employed by the Lazarus Group since at least December 2019. According to TrendMicro and SentinelOne, it targets Windows, Linux, and macOS systems and operates via a centralized command and control infrastructure that allows adversaries to remotely execute commands, exfiltrate data, and remain stealthy across multiple operating environments. Once installed, Dacls establishes persistence mechanisms on each platform—such as scheduled tasks on Windows, launch agents or daemons on macOS, and init scripts on Linux—to ensure it survives reboots. It injects itself into legitimate processes to evade detection and communicates with its C2 server over encrypted channels, often using custom protocol binaries that mimic legitimate traffic. Beyond remote control, the malware can capture screenshots, log keystrokes, steal credentials from browsers, and exfiltrate files via HTTP/HTTPS or FTP. The Lazarus Group has previously leveraged Dacls for data theft during several large‐scale operations in Asia and the Middle East, indicating its role in broader espionage campaigns. Overall, Dacls showcases a modular architecture where additional plug‑in components can be downloaded at runtime, allowing attackers to tailor the payload to specific objectives such as industrial reconnaissance or credential harvesting.

Key Capabilities

  • Remote code execution
  • Persistent installation across platforms
  • Keylogging
  • Screenshot capture
  • Credential theft from browsers
  • Data exfiltration via HTTP/HTTPS and FTP
  • Process injection for stealth
  • Dynamic plugin download for added functionality

ATT&CK Techniques

T1059
T1064
T1018
T1070
T1041
T1086
T1053

Recommended Actions

  • Block known malicious IP addresses, domains, and TLS SNI endpoints linked to Dacls C2 servers.
  • Deploy endpoint detection and response (EDR) solutions that detect process injection, suspicious scheduled tasks, and abnormal file‑system changes on all platforms.
  • Implement network segmentation and strict firewall rules to limit outbound traffic to unknown or high‑risk destinations.
  • Use host‐based intrusion detection systems to monitor for known malware signatures and anomalous keylogging behavior.
  • Apply least privilege principles and regular patching to mitigate exploitation vectors.
  • Configure threat intelligence feeds to surface new indicators of compromise (IOCs) related to Dacls.

Suggested Tags

Remote Access Trojan
Lazarus Group
Cross-Platform
Malware Family
Data Exfiltration
Keylogging
Persistent Threat

Confidence Assessment

The available information is limited to a handful of incident reports. While the association with Lazarus Group and cross‑platform support are well documented, technical details about command sets, persistence mechanisms, and C2 protocols remain incomplete. Confidence in basic malware capabilities is moderate; however, knowledge gaps exist regarding the full scope of its feature set and deployment patterns.

Description

Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.(Citation: TrendMicro macOS Dacls May 2020)(Citation: SentinelOne Lazarus macOS July 2020)

Details

Type
Malware
Platforms
Macos
Linux
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.