DCRat, also known as DarkCrystal RAT, is a .NET-based remote-access trojan targeting Windows systems. It provides attackers with remote control and surveillance capabilities, including mouse control, screenshot capture, window tracking, clipboard access, audio-device discovery, and Windows Registry read/write operations. Observed builds also support keystroke logging, webcam access, desktop browsing, and theft of browser credentials and cryptocurrency-wallet information.
DCRat is distributed through phishing, malicious attachments, fake CAPTCHA lures, and fraudulent game downloads. Documented campaigns have targeted Canadian organizations and Latin American recipients, particularly in Colombia, using invoice, judicial-notification, and tax-authority themes. Malicious game packages containing DCRat have been promoted through poisoned search results, gaming forums, torrent sites, and social media, sometimes alongside other remote-access trojans, information stealers, and destructive malware.
Delivery chains employ scripted loaders, encrypted payloads, DLL sideloading, and process hollowing to execute DCRat inside trusted Windows processes. Analyzed client stubs perform anti-analysis checks, delay execution, establish persistence, and attempt to bypass AMSI. Some deployments block security-vendor telemetry through host-resolution changes. DCRat can decrypt its configuration with AES-256 and communicate with command-and-control servers over TLS, using keep-alive messages and repeated reconnection attempts. DCRat samples have communicated with infrastructure associated with Sable Squirrel, although this infrastructure overlap does not establish exclusive operator attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office. | These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882.
Associated Analytic Story ... DarkCrystal RAT
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Seqrite/Mallory attributed a look-alike sample (Tax_Assessment.exe + libsvcs.dll > XWorm/DcRAT) to Silver Fox with medium-to-high confidence.”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
CERT-UA received information about targeted cyberattacks against Ukrainian civil servants, military personnel, and representatives of defense enterprises using the DarkCrystal RAT malware, which is distributed via the Signal messenger.
DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
24 distinct techniques documented for this family, organized by ATT&CK tactic.
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
Once executed, get.js copies several campaign components... The JavaScript then launches g.bat... Systems that do not match these checks follow a PowerShell based execution path... [other systems] execute the 64-bit AS branch through w.py.
Systems that do not match these checks follow a PowerShell based execution path using hidden loaders... the 32-bit AB branch continues to use SysWOW64 PowerShell.
The JavaScript then launches g.bat with the arguments general x while suppressing the visible command window.
NJRAT supports desktop monitoring and screenshots; Mercurial Grabber collects screenshots; DCRAT provides screenshot capture.
DCRAT provides capabilities including screenshot capture, mouse control, audio-device discovery, window tracking, clipboard access, and registry read/write functionality.
NJRAT communicates with AWS-hosted IP addresses and the ngrok tunneling endpoint 7.tcp.eu.ngrok[.]io:12684; DCRAT communicates with a0700877.xsph[.]ru.
The shortcut... uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file... additional components can be retrieved and staged remotely. | The infection chain used a document themed lure to move victims into attacker controlled staging infrastructure... it uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file.
486 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
194 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commodity remote-access trojan delivered via SVG-based attachment chains in documented Latin American campaigns.
A remote-access trojan deployed through the campaign's shared orchestration framework. It provides one of three independent remote-control paths and uses 212.227.50[.]164:3232 as its identified C2 endpoint.
Mentioned as malware from a separate comparison campaign, not as a payload in the analyzed activity.
Mentioned as the payload in a separate, look-alike Silver Fox-attributed campaign, not as payload used in the analyzed PAPERMILL chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.