Skip to content
Malware family Windows

DcRAT

DcRAT, also known as DarkCrystal RAT, is a Windows remote access trojan in the AsyncRAT lineage and one of the most widely observed descendants of that ecosystem.

Profile source: Mallory opens in a new tab

DcRAT

Family profile

DcRAT, also known as DarkCrystal RAT, is a Windows remote access trojan in the AsyncRAT lineage and one of the most widely observed descendants of that ecosystem. It has been active since at least 2018 and is commonly distributed under a malware-as-a-service model, lowering the barrier to entry for criminal operators. The malware is modular and supports a broad plugin architecture that extends core remote administration with surveillance, credential and information theft, and other post-compromise functions.

DcRAT is used across both cybercrime and espionage activity. It has appeared in phishing-led intrusions, including tax-themed spearphishing operations targeting Indian taxpayers, finance personnel, and related organizations, as well as in broader malware delivery chains that also deploy other RATs and stealers. It has also been distributed through social-engineering schemes involving fake software, cheats, cracks, gaming bots, and trojanized utilities, including ClickFix-style lures and malicious archives promoted through online platforms.

On infected Windows systems, DcRAT commonly provides persistent remote access and extensive host control. Reported capabilities include victim profiling, command execution, screenshot capture, webcam and microphone access through plugins, keylogging, password and file theft, and exfiltration of collected data. Some variants and associated plugins support DLL injection and other process-injection techniques. The malware has also been observed using scheduled tasks or Windows services for persistence, and some campaigns deploy it filelessly through .NET loaders that decrypt and execute payloads directly in memory.

DcRAT places strong emphasis on defense evasion. Documented behaviors include patching Microsoft AMSI to bypass scanning, patching ETW in some variants, anti-analysis and anti-sandbox checks, and use of timing delays such as the w32tm stripchart technique. Communications are typically encrypted, with SSL/TLS-based command and control widely reported; some variants support certificate-based authentication and can be identified by characteristic self-signed certificate metadata inherited across the AsyncRAT family.

The malware is associated with a wide range of operators rather than a single threat actor. It has been linked to criminal MaaS distribution, phishing campaigns targeting Russian-speaking users, multi-family loader ecosystems, and China-aligned activity such as Operation DragonReturn, which used a multi-stage infection chain, AMSI bypass, service persistence, and covert data collection against India-focused targets. Its continued evolution, plugin ecosystem, and widespread reuse make DcRAT a durable and versatile threat in the Windows malware landscape.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
16 IP / 3 hostnames

Leading locations

  • US3
  • DE2
  • SE2
  • AE1
  • BG1
  • CA1
  • CH1
  • CN1
  • GB1
  • HK1
  • IR1
  • LU1

Leading providers

  • Glesys AB2
  • Paradise Networks LLC2
  • CHINA UNICOM China169 Backbone1
  • Cloudflare, Inc.1
  • CTG Server Limited1
  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 16
  • Vpn 4
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
qwqdanchun

AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)

Silver Fox

The "Mixed Reality.exe" binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine.

NyashTeam

The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.

APT-C-36

TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.

UAC-0200

"The campaign ultimately deploys DCRat, a Russia-linked remote access Trojan (RAT)."

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

TA584

Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT, which was still seen in one case in 2025.

Exploited software

Vulnerabilities linked to DcRAT

1 CVEs

MITRE ATT&CK

DcRAT in ATT&CK

94 distinct techniques

Techniques

94 techniques
T1583.003 Virtual Private Server T1588.001 Malware T1071 Application Layer Protocol T1587.001 Malware T1219 Remote Access Tools T1547.009 Shortcut Modification T1620 Reflective Code Loading T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1497 Virtualization/Sandbox Evasion T1055.012 Process Hollowing T1027.003 Steganography T1068 Exploitation for Privilege Escalation T1059.001 PowerShell T1562.001 Disable or Modify Tools T1113 Screen Capture T1548.002 Bypass User Account Control T1140 Deobfuscate/Decode Files or Information T1566.002 Spearphishing Link T1055 Process Injection T1036 Masquerading T1041 Exfiltration Over C2 Channel T1543.003 Windows Service T1566 Phishing T1204.002 Malicious File T1106 Native API T1027 Obfuscated Files or Information T1082 System Information Discovery T1057 Process Discovery T1518.001 Security Software Discovery T1095 Non-Application Layer Protocol T1059.003 Windows Command Shell T1568 Dynamic Resolution T1547.001 Registry Run Keys / Startup Folder T1010 Application Window Discovery T1071.001 Web Protocols T1005 Data from Local System T1573 Encrypted Channel T1033 System Owner/User Discovery T1059 Command and Scripting Interpreter T1056.001 Keylogging T1560 Archive Collected Data T1125 Video Capture T1555 Credentials from Password Stores T1123 Audio Capture T1539 Steal Web Session Cookie T1486 Data Encrypted for Impact T1562.004 Disable or Modify System Firewall T1127.001 MSBuild T1053.005 Scheduled Task T1055.001 Dynamic-link Library Injection T1105 Ingress Tool Transfer T1059.007 JavaScript T1497.003 Time Based Checks T1529 System Shutdown/Reboot T1195 Supply Chain Compromise T1562 Impair Defenses T1055.004 Asynchronous Procedure Call T1497.001 System Checks T1574.001 DLL T1059.006 Python T1218.005 Mshta T1027.013 Encrypted/Encoded File T1091 Replication Through Removable Media T1036.005 Match Legitimate Resource Name or Location T1583.006 Web Services T1564.001 Hidden Files and Directories T1025 Data from Removable Media T1204 User Execution T1027.002 Software Packing T1112 Modify Registry T1102.001 Dead Drop Resolver T1573.001 Symmetric Cryptography T1008 Fallback Channels T1572 Protocol Tunneling T1115 Clipboard Data T1555.003 Credentials from Web Browsers T1090.002 External Proxy T1665 Hide Infrastructure T1571 Non-Standard Port T1573.002 Asymmetric Cryptography T1070.004 File Deletion T1568.002 Domain Generation Algorithms T1197 BITS Jobs T1036.007 Double File Extension T1083 File and Directory Discovery T1120 Peripheral Device Discovery T1547 Boot or Logon Autostart Execution T1498 Network Denial of Service T1070.006 Timestomp T1104 Multi-Stage Channels T1132.001 Standard Encoding T1124 System Time Discovery T1566.003 Spearphishing via Service

Reporting

Research mentioning DcRAT

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

DCRAT4

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

DCRAT4

Jul 6
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

The "Mixed Reality.exe" binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine.

Jun 30
Cyberveille

AsyncRAT Family : cartographie de 40 variants RAT et leur infrastructure C2 active | CyberVeille

AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)

Jun 29
Gurucul Threat Research

Operation DragonReturn: China-Nexus Campaign Targeting India's Tax Infrastructure via DcRAT | Community Portal | Gurucul

Operation DragonReturn: China-Nexus Campaign Targeting India's Tax Infrastructure via DcRAT

Jun 26
Malware News

Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment - Malware Analysis - Malware Analysis, News and Indicators

Operation DragonReturn represents a sophisticated and actively maintained China-Nexus cyber espionage campaign ... and a multi-stage DcRAT deployment chain leveraging steganographic payload concealment within background.jpg, fileless .NET execution, AMSI bypass, Windows service persistence under the guise of Mixed Reality Service, and encrypted TLS-based C2 communications...

Jun 26
Seqrite

Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment | Seqrite

Operation DragonReturn represents a sophisticated and actively maintained China-Nexus cyber espionage campaign ... and a multi-stage DcRAT deployment chain leveraging steganographic payload concealment within background.jpg, fileless .NET execution, AMSI bypass, Windows service persistence under the guise of Mixed Reality Service, and encrypted TLS-based C2 communications ...

May 22
Cyber Security News

Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access

Indicators of Compromise (IoCs):- ... Malware DarkCrystal RAT Remote access trojan deployed post-compromise

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.