DarkTortilla is a Windows malware family best characterized as a loader that delivers additional malicious payloads and modules after initial execution. It has been observed distributed through spearphishing emails carrying archive attachments and malicious documents, relying on user interaction to open the lure file. After execution, DarkTortilla performs host and environment discovery, including use of WMI queries to gather system information, inspection of running services, internet connectivity checks via HTTP requests, and checks for installed security software such as antivirus products. It also incorporates anti-analysis behavior, including debugger and profiler detection, and can adapt its execution in defended environments.
The malware supports persistence on Windows systems through registry modification and by creating a shortcut in the Startup folder via the WshShortcut COM object. It can retrieve follow-on payloads from public text-hosting services and has been documented downloading additional modules including keylogging and clipboard-stealing components. DarkTortilla also supports process injection through a .NET RunPE-style component, enabling in-memory execution of payloads and additional defense evasion. Its observed tradecraft aligns with commodity malware delivery operations that use phishing-based initial access to establish a foothold and then stage secondary malware on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
Examples include "DarkTortilla can obtain system information by querying the Win32_ComputerSystem, Win32_BIOS, Win32_MotherboardDevice, Win32_PnPEntity, and Win32_DiskDrive WMI objects" and "Kimsuky has also obtained system information ... through querying various Windows Management Instrumentation (WMI) classes including Win32_OperatingSystem."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
Multiple actors and malware check for internet/network connectivity using ping, tracert, HTTP GET requests, or contacting well-known domains (e.g., google[.]com, bing[.]com, 8.8.8.8) prior to tool transfer or C2 establishment.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
“APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads… EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads… Bumblebee has been downloaded… from OneDrive… Operation Spalax… used OneDrive and MediaFire to host payloads… Raspberry Robin… payloads… on Discord servers.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based crypter and loader used to distribute and execute next-stage malware payloads, such as Formbook, often employing obfuscation and evasion techniques.
Modular .NET loader used in malspam-driven infection chains to deploy commodity malware. In this campaign, a 32-bit VB.NET executable (QNaZg.exe) decrypts an embedded DLL using a reverse+conditional XOR routine and reflectively loads it into memory, then uses .NET reflection/late binding to invoke the payload.
A loader that checks for internet connectivity via HTTP GET requests.
Malware delivered via malicious documents or archives sent by email.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.