Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 16 IP / 3 hostnames
DcRAT, also known as DarkCrystal RAT, is a Windows remote access trojan in the AsyncRAT lineage and one of the most widely observed descendants of that ecosystem.
Profile source: Mallory opens in a new tabDcRAT
DcRAT, also known as DarkCrystal RAT, is a Windows remote access trojan in the AsyncRAT lineage and one of the most widely observed descendants of that ecosystem. It has been active since at least 2018 and is commonly distributed under a malware-as-a-service model, lowering the barrier to entry for criminal operators. The malware is modular and supports a broad plugin architecture that extends core remote administration with surveillance, credential and information theft, and other post-compromise functions.
DcRAT is used across both cybercrime and espionage activity. It has appeared in phishing-led intrusions, including tax-themed spearphishing operations targeting Indian taxpayers, finance personnel, and related organizations, as well as in broader malware delivery chains that also deploy other RATs and stealers. It has also been distributed through social-engineering schemes involving fake software, cheats, cracks, gaming bots, and trojanized utilities, including ClickFix-style lures and malicious archives promoted through online platforms.
On infected Windows systems, DcRAT commonly provides persistent remote access and extensive host control. Reported capabilities include victim profiling, command execution, screenshot capture, webcam and microphone access through plugins, keylogging, password and file theft, and exfiltration of collected data. Some variants and associated plugins support DLL injection and other process-injection techniques. The malware has also been observed using scheduled tasks or Windows services for persistence, and some campaigns deploy it filelessly through .NET loaders that decrypt and execute payloads directly in memory.
DcRAT places strong emphasis on defense evasion. Documented behaviors include patching Microsoft AMSI to bypass scanning, patching ETW in some variants, anti-analysis and anti-sandbox checks, and use of timing delays such as the w32tm stripchart technique. Communications are typically encrypted, with SSL/TLS-based command and control widely reported; some variants support certificate-based authentication and can be identified by characteristic self-signed certificate metadata inherited across the AsyncRAT family.
The malware is associated with a wide range of operators rather than a single threat actor. It has been linked to criminal MaaS distribution, phishing campaigns targeting Russian-speaking users, multi-family loader ecosystems, and China-aligned activity such as Operation DragonReturn, which used a multi-stage infection chain, AMSI bypass, service persistence, and covert data collection against India-focused targets. Its continued evolution, plugin ecosystem, and widespread reuse make DcRAT a durable and versatile threat in the Windows malware landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
17c9c84fb08d55bf21f02427f7d310a9fe2f7b08e275ef1128ff4f2ce8f13748 387391c584c4016813d8d25eac2da282ec84322b911bb7af1a706af2e10017e9 52328a11efe66bc17fed31a314b9605f0b6602cf51a2dd7711635aa9dc45bb1f 85dbc109291f097c50e2cbc8af437781eeeed9c79dd247952755b299ab336422 efa8bb9f6792898f5435a47d3f644bdeae41f1ac793e283959cce6ac4f639444 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 Reported operators
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
The "Mixed Reality.exe" binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine.
The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
"The campaign ultimately deploys DCRat, a Russia-linked remote access Trojan (RAT)."
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT, which was still seen in one case in 2025.
Exploited software
MITRE ATT&CK
Reporting
DCRAT4
DCRAT4
The "Mixed Reality.exe" binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
Operation DragonReturn: China-Nexus Campaign Targeting India's Tax Infrastructure via DcRAT
Operation DragonReturn represents a sophisticated and actively maintained China-Nexus cyber espionage campaign ... and a multi-stage DcRAT deployment chain leveraging steganographic payload concealment within background.jpg, fileless .NET execution, AMSI bypass, Windows service persistence under the guise of Mixed Reality Service, and encrypted TLS-based C2 communications...
Operation DragonReturn represents a sophisticated and actively maintained China-Nexus cyber espionage campaign ... and a multi-stage DcRAT deployment chain leveraging steganographic payload concealment within background.jpg, fileless .NET execution, AMSI bypass, Windows service persistence under the guise of Mixed Reality Service, and encrypted TLS-based C2 communications ...
Indicators of Compromise (IoCs):- ... Malware DarkCrystal RAT Remote access trojan deployed post-compromise
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.