LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0694: DRATzarus

DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally since at least summer 2020. DRATzarus shares similarities with Bankshot, which was used by Lazarus Group in 2017 to target the Turkish financial sector.[1]

EnterpriseS0694MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DRATzarus matters because it represents a Windows remote access tool associated in ATT&CK with Lazarus Group activity against defense and aerospace organizations. For leaders, the practical issue is not the malware name alone; it is whether the organization can quickly prove visibility into remote access behavior, local data collection, host and user discovery, tool transfer, and web-based command-and-control patterns if a similar RAT appears in a sensitive environment.

Executive priority

Prioritize this as an espionage-relevant remote access capability tied to sectors where intellectual property, national security programs, regulated data, and operational continuity are material. Executives should ask whether SOC and incident response teams can validate Windows endpoint coverage, web egress visibility, malware-analysis readiness for packed or obfuscated files, and evidence preservation for discovery and collection activity. For compliance and risk owners, the value is demonstrating that controls and logs can support investigation of unauthorized remote access, data staging, and command-and-control behavior rather than relying only on known malware signatures.

Technical view

ATT&CK lists DRATzarus as Windows malware with no official detection text, so defenders should build validation around the related behaviors: Data from Local System, Remote System Discovery, Obfuscated Files or Information, Software Packing, System Owner/User Discovery, Match Legitimate Resource Name or Location, Process Discovery, Web Protocols, Ingress Tool Transfer, Native API, System Time Discovery, Time Based Checks, and Debugger Evasion. SOC teams should confirm that Windows endpoint telemetry can show suspicious process execution, process and user enumeration, unusual file access or collection patterns, masqueraded file names or locations, and tool downloads. Network teams should validate visibility into HTTP/S or other web-protocol command-and-control-like traffic while accounting for the high false-positive rate of normal web traffic.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • File creation, modification, access, and suspicious placement telemetry
  • Endpoint detection alerts for packed, obfuscated, or masqueraded executables
  • User and logged-on session discovery evidence
  • Process enumeration and system discovery events

Detection direction

  • Do not depend only on the DRATzarus name or static signatures; ATT&CK provides no official detection guidance for this object.
  • Validate behavior-based detections for Windows discovery activity, including user, process, remote system, and system time discovery.
  • Tune web-protocol command-and-control analytics against normal business web traffic to reduce false positives while preserving visibility into unusual destinations, timing, and host context.
  • Look for suspicious file placement or names that approximate legitimate resources, especially when combined with new executable creation or unexpected execution.
  • Correlate packed or obfuscated binaries with execution, network egress, and follow-on discovery rather than treating packing alone as conclusive.

Mitigation priorities

  • Maintain strong Windows endpoint prevention and monitoring coverage on systems that handle sensitive defense, aerospace, government, or high-value business data.
  • Restrict and monitor outbound web traffic where operationally feasible, with proxy, DNS, and firewall logging retained for investigations.
  • Harden least-privilege access and reduce unnecessary local data exposure so local collection from a compromised endpoint has less business impact.
  • Control software execution and file download paths through application control, endpoint policy, and user privilege management where appropriate.
  • Prepare incident response playbooks for suspected RAT activity, including host isolation, memory and disk collection, credential exposure review, and egress analysis.
Additional notes and limits

The supplied ATT&CK object identifies DRATzarus as a RAT used by Lazarus Group and related to Operation Dream Job, with historical targeting of defense and aerospace organizations and additional campaign context involving defense, aerospace, government, and other sectors. The most useful defensive framing is behavior-led: remote access, discovery, data collection, obfuscation, masquerading, tool transfer, and web-protocol communications on Windows systems.

MITRE provides no official detection text, no aliases, no explicit tactics on the malware object, and only the supplied relationships define the behavioral scope here. Local telemetry, baselines, asset criticality, and confirmed indicators are required before assessing exposure, incident impact, or detection coverage. The presence of related ATT&CK techniques does not prove current exploitation or compromise in any environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DRATzarus

DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally since at least summer 2020. DRATzarus shares similarities with Bankshot, which was used by Lazarus Group in 2017 to target the Turkish financial sector.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

13 rows
DomainIDNameRelationship / procedure
EnterpriseT1033System Owner/User Discovery

DRATzarus can obtain a list of users from an infected machine.[1]

EnterpriseT1622Debugger Evasion

DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim.[1]

EnterpriseT1124System Time Discovery

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time.[1]

EnterpriseT1005Data from Local System

DRATzarus can collect information from a compromised host.[1]

EnterpriseT1105Ingress Tool Transfer

DRATzarus can deploy additional tools onto an infected machine.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`.[1]

EnterpriseT1018Remote System Discovery

DRATzarus can search for other machines connected to compromised host and attempt to map the network.[1]

EnterpriseT1106Native API

DRATzarus can use various API calls to see if it is running in a sandbox.[1]

EnterpriseT1027.002Software PackingSub-technique

DRATzarus's dropper can be packed with UPX.[1]

EnterpriseT1057Process Discovery

DRATzarus can enumerate and examine running processes to determine if a debugger is present.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

DRATzarus can use HTTP or HTTPS for C2 communications.[1]

EnterpriseT1497.003Time Based ChecksSub-technique

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing.[1] DRATzarus can also remotely shut down into sleep mode under specific conditions to evade detection.[1]

EnterpriseT1027Obfuscated Files or Information

DRATzarus can be partly encrypted with XOR.[1]

Associated objects

Groups, software, and campaigns

CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
c333853570d92ccf...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundlec333853570d9…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  2. [2]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  3. [3]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  4. [4]
    mitre-attackS0694
    Open source URL
  5. [5]
    mitre-attackS0694
    Open source URL
  6. [6]
    mitre-attackS0694
    Open source URL
  7. [7]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  8. [8]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  9. [9]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  10. [10]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  11. [11]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  12. [12]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  13. [13]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  14. [14]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  15. [15]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  16. [16]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  17. [17]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  18. [18]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  19. [19]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  20. [20]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  21. [21]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  22. [22]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  23. [23]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  24. [24]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  25. [25]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  26. [26]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  27. [27]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  28. [28]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  29. [29]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  30. [30]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  31. [31]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  32. [32]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.