DcRAT, also known as DarkCrystal RAT, is a Windows remote access trojan in the AsyncRAT lineage and one of the most widely observed descendants of that ecosystem. It has been active since at least 2018 and is commonly distributed under a malware-as-a-service model, lowering the barrier to entry for criminal operators. The malware is modular and supports a broad plugin architecture that extends core remote administration with surveillance, credential and information theft, and other post-compromise functions.
DcRAT is used across both cybercrime and espionage activity. It has appeared in phishing-led intrusions, including tax-themed spearphishing operations targeting Indian taxpayers, finance personnel, and related organizations, as well as in broader malware delivery chains that also deploy other RATs and stealers. It has also been distributed through social-engineering schemes involving fake software, cheats, cracks, gaming bots, and trojanized utilities, including ClickFix-style lures and malicious archives promoted through online platforms.
On infected Windows systems, DcRAT commonly provides persistent remote access and extensive host control. Reported capabilities include victim profiling, command execution, screenshot capture, webcam and microphone access through plugins, keylogging, password and file theft, and exfiltration of collected data. Some variants and associated plugins support DLL injection and other process-injection techniques. The malware has also been observed using scheduled tasks or Windows services for persistence, and some campaigns deploy it filelessly through .NET loaders that decrypt and execute payloads directly in memory.
DcRAT places strong emphasis on defense evasion. Documented behaviors include patching Microsoft AMSI to bypass scanning, patching ETW in some variants, anti-analysis and anti-sandbox checks, and use of timing delays such as the w32tm stripchart technique. Communications are typically encrypted, with SSL/TLS-based command and control widely reported; some variants support certificate-based authentication and can be identified by characteristic self-signed certificate metadata inherited across the AsyncRAT family.
The malware is associated with a wide range of operators rather than a single threat actor. It has been linked to criminal MaaS distribution, phishing campaigns targeting Russian-speaking users, multi-family loader ecosystems, and China-aligned activity such as Operation DragonReturn, which used a multi-stage infection chain, AMSI bypass, service persistence, and covert data collection against India-focused targets. Its continued evolution, plugin ecosystem, and widespread reuse make DcRAT a durable and versatile threat in the Windows malware landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
The "Mixed Reality.exe" binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine.
The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
"The campaign ultimately deploys DCRat, a Russia-linked remote access Trojan (RAT)."
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Tags Malware Threat Actor China-Nexus Government Services and Facilities China DCRAT Financial Services Cyber Espionage Asia India ... Phishing ... Spear Phishing
a hunting event revealed execution of an obfuscated PowerShell... The code chains led us to a double download
Upon execution, the malicious executable spawns multiple cmd.exe processes that leverage the Windows Service Control (sc.exe) utility to create a service named MixedSvc.
achieving persistence by dropping a VBS that acted as a loader for the entire execution, which invoked wscript
establishes persistence by creating a Windows service named MixedSvc, configured to start automatically on system boot
a malicious DLL ("nvdaHelperRemote.dll"), which, in turn, injects another payload into memory
The end result was an in-memory load of the first binary’s code, which has capabilities to obtain process information and perform injections, specifically process hollowing.
checking the current privileges to try to escalate them, attempting to run with the highest privileges possible
establishes persistence by creating a Windows service named MixedSvc, configured to start automatically on system boot
The sample also performs registry operations using RegOpenKeyExA(), RegCreateKeyExA(), and RegSetValueExA(), indicating the creation of configuration or persistence-related registry values.
The analysed function begins by DE obfuscating several strings using a simple XOR operation (^ 0x18 and ^ 0x02).
The code chains led us to a double download, one of which used steganography (so it was embedded in an image)
The bogus landing page... instructs users to download a ZIP archive containing what appears to be a common offline utility provided by the department to file tax returns
a malicious DLL ("nvdaHelperRemote.dll"), which, in turn, injects another payload into memory
The end result was an in-memory load of the first binary’s code, which has capabilities to obtain process information and perform injections, specifically process hollowing.
disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine
Following payload preparation, the malware enumerates running processes using CreateToolhelp32Snapshot() and searches specifically for svchost.exe.
The IdSender.SendInfo() routine collects a wide range of host information, including the victim’s hardware identifier (HWID), username, operating system version and architecture, executable path, malware version, privilege level... installed antivirus products... and system idle time.
155 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
126 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DCRAT4
DCRAT4
A remote access trojan delivered via a multi-stage phishing campaign impersonating the Indian Income Tax Department. In this campaign it is loaded by a .NET malware loader after anti-analysis checks, persistence setup, and AMSI bypass, enabling covert access and data theft from infected hosts.
Prolific descendant/fork of AsyncRAT whose inherited TLS certificate structure is described as the most reliable detection signal across the family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.