Skip to content

DcRAT

DCRat, also known as DarkCrystal RAT, is a modular Windows remote-access trojan and backdoor that has been sold on Russian-language cybercriminal forums since 2018.

Profile source: Mallory opens in a new tab

DcRAT

Family profile

DCRat, also known as DarkCrystal RAT, is a modular Windows remote-access trojan and backdoor that has been sold on Russian-language cybercriminal forums since 2018. It is derived from AsyncRAT source code and retains closely related configuration and TLS certificate-validation behavior. DCRat provides operators with remote control of compromised endpoints and supports modular surveillance and information-theft functions, including keylogging, credential theft, screenshot capture, host and file discovery, and data exfiltration.

DCRat has been delivered through phishing and spearphishing campaigns, including judicial, government, tax, and diplomatic lures. Observed chains have used malicious Office documents exploiting CVE-2017-11882, SVG attachments implementing HTML smuggling, and social-engineering sites offering cryptocurrency-related lures. Delivery chains commonly use script-based loaders and trusted Windows components, then employ DLL sideloading, in-memory payload reconstruction, and process hollowing to execute the RAT within legitimate processes. Snip3 crypter-based campaigns have also compiled injection code dynamically on victim systems before hollowing legitimate processes to run DCRat.

The malware can establish persistence through Windows startup mechanisms or Registry Run entries, delay execution, enforce single-instance operation, conduct anti-analysis checks, attempt AMSI bypass, and remove traces when executed with elevated privileges. Its configuration is encrypted and can include command-and-control settings, installation options, anti-analysis settings, and certificate material. DCRat communicates with command-and-control infrastructure over TLS, uses keep-alive and reconnection logic, and implements certificate-validation techniques intended to hinder interception. It has appeared in campaigns targeting Colombian users, Indian and Afghan government or diplomatic entities, Ukrainian organizations, and cryptocurrency users. DarkCrystal RAT was also reported in activity targeting Ukrainian media and telecommunications organizations that was associated with Sandworm at medium confidence.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
47 IP / 16 hostnames

Leading locations

  • US17
  • NL8
  • DE7
  • CN6
  • HK5
  • RU4
  • SE3
  • SG3
  • CA2
  • FR2
  • CH1
  • FI1

Leading providers

  • 1337 Services GmbH3
  • CTG Server Limited3
  • Glesys AB3
  • HosterDaddy Private Limited3
  • JSC IOT3
  • Paradise Networks LLC3

Infrastructure traits

  • Hosting 57
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

Sandworm

...dcrat.exe (2022-05-04) (DarkCrystal RAT)

UAC-0200

CERT-UA received information about targeted cyberattacks against Ukrainian civil servants, military personnel, and representatives of defense enterprises using the DarkCrystal RAT malware, which is distributed via the Signal messenger.

RedFoxtrot

DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.

Silver Fox

...the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat.

qwqdanchun

AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)

NyashTeam

The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.

APT-C-36

TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

TA584

Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT, which was still seen in one case in 2025.

Exploited software

Vulnerabilities linked to DcRAT

2 CVEs

MITRE ATT&CK

DcRAT in ATT&CK

118 distinct techniques

Techniques

118 techniques
T1071 Application Layer Protocol T1204.002 Malicious File T1140 Deobfuscate/Decode Files or Information T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1059.003 Windows Command Shell T1573.001 Symmetric Cryptography T1547.001 Registry Run Keys / Startup Folder T1071.001 Web Protocols T1055.012 Process Hollowing T1059.007 JavaScript T1106 Native API T1036 Masquerading T1059 Command and Scripting Interpreter T1204 User Execution T1566 Phishing T1105 Ingress Tool Transfer T1584 Compromise Infrastructure T1027.013 Encrypted/Encoded File T1056.001 Keylogging T1115 Clipboard Data T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1497 Virtualization/Sandbox Evasion T1070.004 File Deletion T1123 Audio Capture T1112 Modify Registry T1059.005 Visual Basic T1037.001 Logon Script (Windows) T1055 Process Injection T1125 Video Capture T1203 Exploitation for Client Execution T1047 Windows Management Instrumentation T1543 Create or Modify System Process T1539 Steal Web Session Cookie T1070 Indicator Removal T1053.005 Scheduled Task T1553.002 Code Signing T1568 Dynamic Resolution T1082 System Information Discovery T1078 Valid Accounts T1497.001 System Checks T1562 Impair Defenses T1562.001 Disable or Modify Tools T1053 Scheduled Task/Job T1219 Remote Access Tools T1189 Drive-by Compromise T1620 Reflective Code Loading T1083 File and Directory Discovery T1548 Abuse Elevation Control Mechanism T1059.006 Python T1056 Input Capture T1001 Data Obfuscation T1027.007 Dynamic API Resolution T1222 File and Directory Permissions Modification T1555 Credentials from Password Stores T1005 Data from Local System T1518 Software Discovery T1622 Debugger Evasion T1129 Shared Modules T1573 Encrypted Channel T1027.006 HTML Smuggling T1583.001 Domains T1055.011 Extra Window Memory Injection T1218.004 InstallUtil T1574.001 DLL T1071.004 DNS T1055.002 Portable Executable Injection T1190 Exploit Public-Facing Application T1113 Screen Capture T1204.001 Malicious Link T1583.003 Virtual Private Server T1588.001 Malware T1587.001 Malware T1547.009 Shortcut Modification T1027.003 Steganography T1068 Exploitation for Privilege Escalation T1548.002 Bypass User Account Control T1566.002 Spearphishing Link T1543.003 Windows Service T1057 Process Discovery T1518.001 Security Software Discovery T1095 Non-Application Layer Protocol T1010 Application Window Discovery T1033 System Owner/User Discovery T1560 Archive Collected Data T1486 Data Encrypted for Impact T1562.004 Disable or Modify System Firewall T1127.001 MSBuild T1055.001 Dynamic-link Library Injection T1497.003 Time Based Checks T1529 System Shutdown/Reboot T1195 Supply Chain Compromise T1055.004 Asynchronous Procedure Call T1218.005 Mshta T1091 Replication Through Removable Media T1036.005 Match Legitimate Resource Name or Location T1583.006 Web Services T1564.001 Hidden Files and Directories T1025 Data from Removable Media T1027.002 Software Packing T1102.001 Dead Drop Resolver T1008 Fallback Channels T1572 Protocol Tunneling T1555.003 Credentials from Web Browsers T1090.002 External Proxy T1665 Hide Infrastructure T1571 Non-Standard Port T1573.002 Asymmetric Cryptography T1568.002 Domain Generation Algorithms T1197 BITS Jobs T1036.007 Double File Extension T1120 Peripheral Device Discovery T1547 Boot or Logon Autostart Execution T1498 Network Denial of Service T1070.006 Timestomp T1104 Multi-Stage Channels T1132.001 Standard Encoding

Reporting

Research mentioning DcRAT

Aug 14
Cyber Security News

DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

A phishing campaign is delivering DarkCrystal RAT (DCRat) through weaponized SVG attachments that use HTML smuggling to drop a password-protected 7z archive onto Windows systems. Researchers said the lure impersonates a Colombian legal notice, “Resolución Denuncia Jurídica,” and presents a fake citizen consultation portal that instructs victims to open the downloaded archive with the password 1601, making the staged delivery appear legitimate while shifting malicious assembly into the victim’s browser to evade email inspection. The attack chain uses double-Base64-encoded JavaScript embedded in the SVG, followed by DLL sideloading with files disguised as Brotli components, persistence through a Windows Registry Run entry, and process hollowing into AddInProcess32.exe. The final payload installs DCRat, a remote access trojan that supports encrypted command-and-control communications, anti-analysis checks, and repeated beaconing to 158[.]94[.]208[.]109, giving attackers sustained access to compromised hosts.

Aug 14
Cryptika

DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling | Cryptika Cybersecurity

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.