Skip to content

Malware

Dtrack

aka Preft · TroyRAT

Dtrack is a Remote Administration Tool (RAT) developed by the Lazarus group.

Dtrack, also known as Preft, TroyRAT, is a Windows malware family operated by Lazarus Group and Silent Chollima.

Background

Dtrack is a Remote Administration Tool (RAT) attributed to the Lazarus group. Its primary capabilities include uploading files to and downloading files from the victim's machine, dumping disk volume data, maintaining persistence, and more.

One Dtrack variant was discovered at the Kudankulam Nuclear Power Plant (KNPP), where it featured in a targeted intrusion.


Source: Malpedia (Fraunhofer FKIE).