Skip to content

DarkTortilla

DarkTortilla is a Windows malware family/loader distributed primarily through spearphishing emails containing archive attachments such as .iso, .zip, .img, .dmg, and .tar, as well as malicious documents.

Profile source: Mallory opens in a new tab

DarkTortilla

Family profile

DarkTortilla is a Windows malware family/loader distributed primarily through spearphishing emails containing archive attachments such as .iso, .zip, .img, .dmg, and .tar, as well as malicious documents. Initial execution relies on user interaction to open the malicious document or archived file delivered via email. Observed capabilities include persistence through registry key modification and creation of a .lnk shortcut in the Windows Startup folder via the WshShortcut COM object; system discovery using WMI queries to obtain system information; retrieval of information about running services; security software discovery, including checks for Kaspersky Anti-Virus; internet connectivity checks via HTTP GET requests; retrieval of its primary payload from public sites such as Pastebin and Textbin; modular payload delivery including clipboard information stealer and keylogging modules; process injection using a .NET-based DLL named RunPe6; and anti-analysis checks that detect debuggers using DebuggerIsAttached and DebuggerIsLogging and detect profilers by verifying whether the COR_ENABLE_PROFILING environment variable is present and active. A reported masquerading behavior is renaming its payload to PowerShellInfo.exe.

MITRE ATT&CK

DarkTortilla in ATT&CK

32 distinct techniques

Reporting

Research mentioning DarkTortilla

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.