DarkTortilla
DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least 2015 and targeting Windows systems.
Profile source: Mallory opens in a new tabDarkTortilla
Family profile
DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least 2015 and targeting Windows systems. It is commonly delivered through logistics-themed spearphishing emails carrying malicious documents, archives, or disk-image attachments that require user interaction. The loader decrypts its core components and runtime configuration in memory, including configuration data concealed in bitmap pixel data, and can retrieve additional components from public paste services.
DarkTortilla supports in-memory payload execution through process injection and has delivered Agent Tesla, AsyncRAT, NanoCore, RedLine, Cobalt Strike, and Metasploit. Its modular architecture can download supplemental payloads, including clipboard-stealing and keylogging modules, as well as other malware, miners, legitimate executables, and decoy documents.
The malware implements configurable persistence through user-level autorun settings, modified logon shell settings, and Startup-folder shortcuts. A mutually monitored watchdog and loader recovery mechanism can restore terminated components, reapply persistence, and reinject payloads. Defense-evasion features include code, string, control-flow, and configuration obfuscation; virtual-machine, debugger, profiler, security-software, process, and service checks; execution delays; payload execution without writing the main payload to disk; and fake error messages. It also uses WMI to collect host information and can test outbound internet connectivity before continuing execution.
Capabilities
- Defense Evasion
- Keylogging
- Persistence
- Process Injection
- Reconnaissance
MITRE ATT&CK
DarkTortilla in ATT&CK
34 distinct techniquesReporting