Executive Summary
Dacls is a cross‐platform RAT that gives Lazarus Group persistent remote access to Windows, Linux, and macOS machines. It supports covert command execution, keylogging, screenshot capture, and data exfiltration over encrypted channels. The malware’s modular design enables attackers to add or update capabilities as needed.
Enhanced Description
Dacls is a sophisticated cross‐platform remote access trojan (RAT) that has been employed by the Lazarus Group since at least December 2019. According to TrendMicro and SentinelOne, it targets Windows, Linux, and macOS systems and operates via a centralized command and control infrastructure that allows adversaries to remotely execute commands, exfiltrate data, and remain stealthy across multiple operating environments. Once installed, Dacls establishes persistence mechanisms on each platform—such as scheduled tasks on Windows, launch agents or daemons on macOS, and init scripts on Linux—to ensure it survives reboots. It injects itself into legitimate processes to evade detection and communicates with its C2 server over encrypted channels, often using custom protocol binaries that mimic legitimate traffic. Beyond remote control, the malware can capture screenshots, log keystrokes, steal credentials from browsers, and exfiltrate files via HTTP/HTTPS or FTP. The Lazarus Group has previously leveraged Dacls for data theft during several large‐scale operations in Asia and the Middle East, indicating its role in broader espionage campaigns. Overall, Dacls showcases a modular architecture where additional plug‑in components can be downloaded at runtime, allowing attackers to tailor the payload to specific objectives such as industrial reconnaissance or credential harvesting.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information is limited to a handful of incident reports. While the association with Lazarus Group and cross‑platform support are well documented, technical details about command sets, persistence mechanisms, and C2 protocols remain incomplete. Confidence in basic malware capabilities is moderate; however, knowledge gaps exist regarding the full scope of its feature set and deployment patterns.
Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.(Citation: TrendMicro macOS Dacls May 2020)(Citation: SentinelOne Lazarus macOS July 2020)