Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 47 IP / 16 hostnames
DCRat, also known as DarkCrystal RAT, is a modular Windows remote-access trojan and backdoor that has been sold on Russian-language cybercriminal forums since 2018.
Profile source: Mallory opens in a new tabDcRAT
DCRat, also known as DarkCrystal RAT, is a modular Windows remote-access trojan and backdoor that has been sold on Russian-language cybercriminal forums since 2018. It is derived from AsyncRAT source code and retains closely related configuration and TLS certificate-validation behavior. DCRat provides operators with remote control of compromised endpoints and supports modular surveillance and information-theft functions, including keylogging, credential theft, screenshot capture, host and file discovery, and data exfiltration.
DCRat has been delivered through phishing and spearphishing campaigns, including judicial, government, tax, and diplomatic lures. Observed chains have used malicious Office documents exploiting CVE-2017-11882, SVG attachments implementing HTML smuggling, and social-engineering sites offering cryptocurrency-related lures. Delivery chains commonly use script-based loaders and trusted Windows components, then employ DLL sideloading, in-memory payload reconstruction, and process hollowing to execute the RAT within legitimate processes. Snip3 crypter-based campaigns have also compiled injection code dynamically on victim systems before hollowing legitimate processes to run DCRat.
The malware can establish persistence through Windows startup mechanisms or Registry Run entries, delay execution, enforce single-instance operation, conduct anti-analysis checks, attempt AMSI bypass, and remove traces when executed with elevated privileges. Its configuration is encrypted and can include command-and-control settings, installation options, anti-analysis settings, and certificate material. DCRat communicates with command-and-control infrastructure over TLS, uses keep-alive and reconnection logic, and implements certificate-validation techniques intended to hinder interception. It has appeared in campaigns targeting Colombian users, Indian and Afghan government or diplomatic entities, Ukrainian organizations, and cryptocurrency users. DarkCrystal RAT was also reported in activity targeting Ukrainian media and telecommunications organizations that was associated with Sandworm at medium confidence.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 291a961e908248f0402d778c427ad877a8adb6a3d2faaa81792ee4772f29ef42 38af4cf0f57f3cae4fb3a83e841e1e04319d8d11f91cffe382829b1fab19d566 41d66ce341d1dcc254fd374300d54a169adf00fed364e5d0b65c447eb63bb12f 96c1a02f53709977a0d3572a1ac35c84281637c86db17bad9458ac96ce3b334e bedcfb39a6d2f47a11e98e944dc789994707d1ee0c4726a2d7559d0d01e270f0 Reported operators
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
...dcrat.exe (2022-05-04) (DarkCrystal RAT)
CERT-UA received information about targeted cyberattacks against Ukrainian civil servants, military personnel, and representatives of defense enterprises using the DarkCrystal RAT malware, which is distributed via the Signal messenger.
DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.
...the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT, which was still seen in one case in 2025.
Exploited software
MITRE ATT&CK
Reporting
A phishing campaign is delivering DarkCrystal RAT (DCRat) through weaponized SVG attachments that use HTML smuggling to drop a password-protected 7z archive onto Windows systems. Researchers said the lure impersonates a Colombian legal notice, “Resolución Denuncia Jurídica,” and presents a fake citizen consultation portal that instructs victims to open the downloaded archive with the password 1601, making the staged delivery appear legitimate while shifting malicious assembly into the victim’s browser to evade email inspection. The attack chain uses double-Base64-encoded JavaScript embedded in the SVG, followed by DLL sideloading with files disguised as Brotli components, persistence through a Windows Registry Run entry, and process hollowing into AddInProcess32.exe. The final payload installs DCRat, a remote access trojan that supports encrypted command-and-control communications, anti-analysis checks, and repeated beaconing to 158[.]94[.]208[.]109, giving attackers sustained access to compromised hosts.
Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.