Skip to content

DarkTortilla

DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least 2015 and targeting Windows systems.

Profile source: Mallory opens in a new tab

DarkTortilla

Family profile

DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least 2015 and targeting Windows systems. It is commonly delivered through logistics-themed spearphishing emails carrying malicious documents, archives, or disk-image attachments that require user interaction. The loader decrypts its core components and runtime configuration in memory, including configuration data concealed in bitmap pixel data, and can retrieve additional components from public paste services.

DarkTortilla supports in-memory payload execution through process injection and has delivered Agent Tesla, AsyncRAT, NanoCore, RedLine, Cobalt Strike, and Metasploit. Its modular architecture can download supplemental payloads, including clipboard-stealing and keylogging modules, as well as other malware, miners, legitimate executables, and decoy documents.

The malware implements configurable persistence through user-level autorun settings, modified logon shell settings, and Startup-folder shortcuts. A mutually monitored watchdog and loader recovery mechanism can restore terminated components, reapply persistence, and reinject payloads. Defense-evasion features include code, string, control-flow, and configuration obfuscation; virtual-machine, debugger, profiler, security-software, process, and service checks; execution delays; payload execution without writing the main payload to disk; and fake error messages. It also uses WMI to collect host information and can test outbound internet connectivity before continuing execution.

Capabilities

  • Defense Evasion
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

MITRE ATT&CK

DarkTortilla in ATT&CK

34 distinct techniques

Reporting

Research mentioning DarkTortilla

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.