DarkTortilla
DarkTortilla is a Windows malware family/loader distributed primarily through spearphishing emails containing archive attachments such as .iso, .zip, .img, .dmg, and .tar, as well as malicious documents.
Profile source: Mallory opens in a new tabDarkTortilla
Family profile
DarkTortilla is a Windows malware family/loader distributed primarily through spearphishing emails containing archive attachments such as .iso, .zip, .img, .dmg, and .tar, as well as malicious documents. Initial execution relies on user interaction to open the malicious document or archived file delivered via email. Observed capabilities include persistence through registry key modification and creation of a .lnk shortcut in the Windows Startup folder via the WshShortcut COM object; system discovery using WMI queries to obtain system information; retrieval of information about running services; security software discovery, including checks for Kaspersky Anti-Virus; internet connectivity checks via HTTP GET requests; retrieval of its primary payload from public sites such as Pastebin and Textbin; modular payload delivery including clipboard information stealer and keylogging modules; process injection using a .NET-based DLL named RunPe6; and anti-analysis checks that detect debuggers using DebuggerIsAttached and DebuggerIsLogging and detect profilers by verifying whether the COR_ENABLE_PROFILING environment variable is present and active. A reported masquerading behavior is renaming its payload to PowerShellInfo.exe.
MITRE ATT&CK
DarkTortilla in ATT&CK
32 distinct techniquesReporting