The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Operation Blacksmith is a Lazarus Group campaign that used at least three malware families written in the D programming language: NineRAT, DLRAT and BottomLoader. Cisco Talos reported that operators exploited Log4Shell on internet-exposed VMware Horizon servers, then used the malware for remote access, file handling and delivery of additional payloads. DLang is a documented implementation choice—not proof that the malware was inherently stealthier or undetectable.
What Operation Blacksmith is
Cisco Talos described Operation Blacksmith in a report published December 11, 2023. The activity was attributed to Lazarus, a North Korean state-linked threat group. Talos also found overlaps with Andariel, which is tracked by other names including Onyx Sleet and PLUTONIUM. The report called the activity a shift in Lazarus’s tactics.
The campaign’s observed victims included a South American agricultural organization, a European manufacturing entity and organizations in the physical-security sector. Talos characterized the broader targeting as global enterprise opportunism; the report does not establish a worldwide victim count for DLang malware.
How the campaign unfolded
- Initial access: Operators exploited CVE-2021-44228, known as Log4Shell, on publicly exposed VMware Horizon servers.
- Reconnaissance and credential access: After gaining access, they gathered information about systems and dumped credentials, including with ProcDump and Mimikatz.
- Access maintenance: A proxy tool called HazyLoad helped maintain access.
- Malware deployment: The operators used DLang malware for remote access and payload delivery. NineRAT provided a Telegram-based command channel; DLRAT offered a separate remote-access and download capability; BottomLoader fetched later payloads.
Talos first observed NineRAT in this campaign in March 2023, targeting a South American agricultural organization, and later observed its use against a European manufacturing entity in September 2023. The report says NineRAT was initially built around May 2022. On July 25, 2024, CISA and partner agencies included NineRAT and DLang in a broader advisory on North Korean cyber activity.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What NineRAT, DLRAT and BottomLoader do
These are distinct tools, not three names for the same malware. Their roles differ across command and control, host interaction and delivery of follow-on payloads.
| Family | Role and communication | Capabilities and distinguishing detail |
|---|---|---|
| NineRAT | Remote-access Trojan; uses Telegram bots and channels for command and control. | Supports commands, results and file transfers over Telegram. Persistence uses service and BAT-script components. |
| DLRAT | Separate remote-access Trojan and downloader; communicates directly with its command-and-control server. | Can collect host information; reconnaissance commands include ver, whoami and getmac. It also supports downloading and uploading files, renaming files, sleeping and self-deletion. |
| BottomLoader | Downloader that retrieves additional payloads through a remote URL and a PowerShell startup mechanism. | Creates a .URL file in the Startup directory to retrieve later payloads, including HazyLoad. |
Why DLang matters—and what it does not establish
Talos’s findings document DLang as the implementation language for these three families. That is relevant to analysts examining samples and building detection coverage, but the language alone does not show that a binary is malicious. Nor do the cited findings demonstrate that DLang automatically makes malware harder to detect. The behavior—such as suspicious persistence, credential dumping or command-and-control activity—is more useful for assessing risk than the programming language by itself.
Rank #2
The three families also should not be taken as a complete count of DLang malware used by North Korean actors. Talos documented at least three in this campaign; the cited reporting does not establish the total number of such malware strains or a worldwide victim tally.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Defensive checks for organizations
The campaign points to practical places for defenders to review. These measures follow the behaviors Talos documented; they are not a basis for treating every DLang-compiled program as hostile.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsQuick Recap
Best Value
Rank #3
- Reduce exposure: Inventory internet-facing Log4j and VMware Horizon systems, prioritize applicable security updates, and verify that exposed services are protected.
- Review endpoint activity: Investigate unexpected use of credential-dumping utilities such as ProcDump or Mimikatz, suspicious service creation, and unusual BAT-script persistence.
- Inspect startup persistence: Look for unexpected
.URLfiles in user or system Startup directories, especially when they lead to remote payload retrieval. - Assess network behavior: Review unusual Telegram bot or channel traffic associated with endpoints, as well as unexpected direct command-and-control communications.
- Investigate the whole chain: Correlate host reconnaissance, file transfers, proxy activity such as HazyLoad, and downloader behavior rather than relying on a DLang signature alone.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

