Skip to content

DarkTortilla

DarkTortilla is a Windows malware family best characterized as a loader that delivers additional malicious payloads and modules after initial execution.

Profile source: Mallory opens in a new tab

DarkTortilla

Family profile

DarkTortilla is a Windows malware family best characterized as a loader that delivers additional malicious payloads and modules after initial execution. It has been observed distributed through spearphishing emails carrying archive attachments and malicious documents, relying on user interaction to open the lure file. After execution, DarkTortilla performs host and environment discovery, including use of WMI queries to gather system information, inspection of running services, internet connectivity checks via HTTP requests, and checks for installed security software such as antivirus products. It also incorporates anti-analysis behavior, including debugger and profiler detection, and can adapt its execution in defended environments.

The malware supports persistence on Windows systems through registry modification and by creating a shortcut in the Startup folder via the WshShortcut COM object. It can retrieve follow-on payloads from public text-hosting services and has been documented downloading additional modules including keylogging and clipboard-stealing components. DarkTortilla also supports process injection through a .NET RunPE-style component, enabling in-memory execution of payloads and additional defense evasion. Its observed tradecraft aligns with commodity malware delivery operations that use phishing-based initial access to establish a foothold and then stage secondary malware on compromised hosts.

Capabilities

  • Defense Evasion
  • Initial Access
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • IE1

Leading providers

  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

DarkTortilla in ATT&CK

32 distinct techniques

Reporting

Research mentioning DarkTortilla

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.