logo

Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware

ID: 6c55c33b-63f2-50ad-b0c8-2e822a69f4ad

STIX ID: report--6c55c33b-63f2-50ad-b0c8-2e822a69f4ad

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2023-12-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Cisco Talos attributes ‘Operation Blacksmith’ to Andariel (a Lazarus Group subdivision), detailing active exploitation of Log4Shell (CVE-2021-44228) to deploy at least three DLang-based malware strains—NineRAT (Telegram-based RAT/C2), BottomLoader (downloader using PowerShell and Startup persistence), and DLRAT (downloader + RAT features)—against organizations in manufacturing, agriculture, and physical security between March and October 2023; the report also highlights a trend of threat actors adopting memory-safe languages for malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.