Mehmet Kadir CIRIK’s Post

View profile for Mehmet Kadir CIRIK, graphic

Cyber Threat Hunter | Incident Responder

Greetings to all of you, Cisco Talos recently discovered a new campaign using at least three new DLang-based malware families, called "Operation Blacksmith," run by the Lazarus Group. Two of these are remote access trojans (RATs), one of which uses Telegram bots and channels as a means of command and control (C2) communication. We track this Telegram-based RAT as "NineRAT" and the non-Telegram-based RAT as "DLRAT". DLang based downloader is followed as "BottomLoader". You can access the detection rule I wrote on this subject from the link. This rule detects all attempts to create persistence via the Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang. SOC Prime #DLang #APT #malware #ransomware #Lazarus #SigmaRule #ThreatHunting #ThreatDetection #Telegram https://lnkd.in/ebiiixug

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics