Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
DarkTortilla is a Windows malware family best characterized as a loader that delivers additional malicious payloads and modules after initial execution.
Profile source: Mallory opens in a new tabDarkTortilla
DarkTortilla is a Windows malware family best characterized as a loader that delivers additional malicious payloads and modules after initial execution. It has been observed distributed through spearphishing emails carrying archive attachments and malicious documents, relying on user interaction to open the lure file. After execution, DarkTortilla performs host and environment discovery, including use of WMI queries to gather system information, inspection of running services, internet connectivity checks via HTTP requests, and checks for installed security software such as antivirus products. It also incorporates anti-analysis behavior, including debugger and profiler detection, and can adapt its execution in defended environments.
The malware supports persistence on Windows systems through registry modification and by creating a shortcut in the Startup folder via the WshShortcut COM object. It can retrieve follow-on payloads from public text-hosting services and has been documented downloading additional modules including keylogging and clipboard-stealing components. DarkTortilla also supports process injection through a .NET RunPE-style component, enabling in-memory execution of payloads and additional defense evasion. Its observed tradecraft aligns with commodity malware delivery operations that use phishing-based initial access to establish a foothold and then stage secondary malware on compromised hosts.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.