DarkCrystal RAT, commonly abbreviated DCRat or DcRAT, is a modular .NET-based remote access trojan and backdoor sold in cybercriminal forums since at least 2018. It is widely used as commodity malware in financially motivated intrusion sets and phishing campaigns, and has also appeared in operations linked by public reporting to actors such as Sandworm and activity targeting government, diplomatic, media, and private-sector organizations. The malware is closely related to AsyncRAT and reuses similar configuration, encryption, and TLS certificate-validation approaches, while maintaining its own branding, configuration artifacts, and plugin ecosystem.
DCRat provides full remote access to compromised Windows systems and supports persistence, encrypted command-and-control communications over TLS, anti-analysis checks, AMSI bypass, and stealthy execution inside legitimate processes. Reported deployments have used DLL sideloading, process hollowing, and in-memory execution to evade endpoint defenses, including injection into trusted Windows processes. Public reporting also describes modular capabilities including credential theft, keylogging, screenshot capture, and broader stealer functionality in some samples. Variants have been observed enforcing single-instance execution with a mutex, selecting command-and-control endpoints from embedded lists or remote paste services, and repeatedly reconnecting to controllers when offline.
Observed delivery chains are diverse. DCRat has been distributed through phishing attachments including SVG, DOCX, and RTF lures; malicious documents exploiting vulnerabilities such as CVE-2017-11882 and CVE-2022-30190; HTML smuggling; cracked-software ecosystems via loaders such as PrivateLoader; fake cryptocurrency giveaway sites; and Foxit PDF social-engineering chains that trick users into launching external commands. It has also been delivered through crypter and loader frameworks such as Snip3, which compile injection code on the victim host and hollow legitimate processes before launching the RAT.
The malware is prevalent across commodity crimeware ecosystems and shared infrastructure. It has been observed alongside families such as Quasar RAT, AsyncRAT, Remcos, RedLine, TVRat, and NanoCore, and has used infrastructure embedded in broader malicious services including expired-domain abuse and malware distribution networks. DCRat primarily targets Windows environments and has been used against sectors including government, media, healthcare, banking, education, and IT. Its combination of low barrier to entry, modularity, and strong overlap with other open-source RAT families has made it a persistent fixture in phishing-led intrusions and multi-stage malware delivery operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office. | These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882.
Associated Analytic Story ... DarkCrystal RAT
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure.
CERT-UA received information about targeted cyberattacks against Ukrainian civil servants, military personnel, and representatives of defense enterprises using the DarkCrystal RAT malware, which is distributed via the Signal messenger.
DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.
...the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
28 distinct techniques documented for this family, organized by ATT&CK tactic.
By abusing trusted Windows utilities and requiring user interaction, the malware blends into legitimate activity and enables in-memory execution.
The malicious RTF would exploit CVE-2012-11882 — a code execution vulnerability in Office — to execute a malicious PowerShell command.
After execution, a folder is created in the user directory, inside it is dropping selfcopy with its dependency DLLs and a batch script.
This malware is propagated via a Microsoft Word document that contains a malicious VBA script.
Upon inspecting the source code, we discovered an embedded JavaScript script containing double Base64-encoded content... It then saves the file as 'DOC-16-ENE-2026 RESOLUCION DENUNCIA JURIDICA.7z' in the user’s downloads folder.
The payload starts a legitimate process, “AddInProcess32.exe,” in a suspended state using CreateProcessInternalW. It then manipulates the thread’s registers with Wow64GetThreadContext and Wow64SetThreadContext, and injects its malicious code into the target process’s memory using WriteProcessMemory.
This is a classic example of HTML Smuggling... the script includes function code to decode the content and uses a Blob function to reconstruct a ZIP file entirely in the browser's memory.
The nature of malware communications with its C&C server(s) has advanced over time, from using plain non-encrypted channels to using custom and standard symmetric ... and asymmetric ... encryption algorithms and protocols (SSL/TLS) to hinder network inspection of such malicious traffic.
The decoy loader pretends to be a genuine program but intentionally includes malicious DLLs... using Brotli-style names helps the malware blend in and look harmless at first glance.
Finally, ResumeThread restarts the process, which now runs the attacker’s code while appearing to be a normal Windows executable.
The chunk of code above writes a timeout and deletion command to a Batch script file and then executes it. This is usually a self-deletion measure for RATs and stealers.
A subset of the streaming domains also function as malware command-and-control (C2), even as they continue to present live streaming content to visitors.
After configuring buffer sizes and creating a TCP socket, it chooses the server’s host and port either by retrieving them from a Pastebin link or by selecting at random from a list of predefined values.
462 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
177 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via phishing that uses SVG attachments, DLL sideloading, and process hollowing to gain stealthy remote access and evade endpoint defenses, including in-memory execution through trusted Windows utilities.
Remote access trojan delivered or supported through command-and-control infrastructure built on re-registered expired domains.
Remote access trojan using the expired-domain infrastructure as command-and-control.
Remote access trojan observed communicating with Sable Squirrel infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.