DarkCrystal RAT, commonly abbreviated DCRat or DcRat, is a Windows remote access trojan and a prolific descendant of AsyncRAT. Active since at least 2018 and widely offered under a malware-as-a-service model, it is used by cybercriminal and espionage-linked operators for persistent remote control, surveillance, data theft, and delivery of additional malicious components. The malware is modular and supports a broad plugin ecosystem that extends core remote administration with functions such as information stealing, keystroke logging, webcam and microphone access, screenshot capture, password theft, file grabbing, and DLL injection. Some reporting also attributes anti-process features, AMSI and ETW patching, and even a ransomware plugin to certain variants or builds.
DCRat is commonly deployed through social engineering and malware delivery chains rather than as a standalone initial payload. Observed distribution methods include phishing and spearphishing lures, tax-themed decoys, malicious archives masquerading as legitimate software, and cracked-software or cheat-themed downloads promoted through online platforms. It has also appeared as a final payload delivered by intermediary loaders that use obfuscation, anti-analysis checks, steganographic concealment, fileless .NET execution, process injection, and persistence mechanisms such as scheduled tasks or Windows services.
The malware has been associated with multiple threat contexts. It has been linked to activity attributed with varying confidence to China-aligned operations, including campaigns overlapping with Silver Fox and the Operation DragonReturn intrusion set targeting India’s tax ecosystem. It has also been observed in broader cybercriminal campaigns targeting Russian-speaking users and in commodity malware delivery operations alongside families such as XWorm, FormBook, and other AsyncRAT-derived tools. DCRat communications have been noted to use TLS, including certificate-based authentication in some cases, and inherited certificate patterns have been used to track infrastructure across the wider AsyncRAT family.
DCRat primarily targets Windows systems and is used across both opportunistic and targeted intrusions. Its combination of remote administration, credential and data theft, persistence, defense evasion, and extensibility has made it one of the most widely deployed AsyncRAT-lineage malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.
...the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
The operator is NyashTeam -- a Russian-speaking MaaS group active since approximately 2022, selling SalatStealer (marketed as "WebRAT") for around 1,199 RUB/month (~$13 USD). They also distribute DCRat.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
"The campaign ultimately deploys DCRat, a Russia-linked remote access Trojan (RAT)."
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Les méthodes d'accès initiales impliquent généralement ... l'exploitation des vulnérabilités pour compromettre les systèmes cibles.
Les méthodes d'accès initiales impliquent généralement des tactiques d'ingénierie sociale
a hunting event revealed execution of an obfuscated PowerShell... The code chains led us to a double download
Dans certains cas, l’infection peut être déclenchée par un document contenant des macros
Dans certains cas, l’infection peut être déclenchée par un document contenant des macros ou par l’exécution d’un programme déguisé en fichier légitime.
a malicious DLL ("nvdaHelperRemote.dll"), which, in turn, injects another payload into memory
The end result was an in-memory load of the first binary’s code, which has capabilities to obtain process information and perform injections, specifically process hollowing.
checking the current privileges to try to escalate them, attempting to run with the highest privileges possible
establishes persistence by creating a Windows service named MixedSvc, configured to start automatically on system boot
The code chains led us to a double download, one of which used steganography (so it was embedded in an image)
The bogus landing page... instructs users to download a ZIP archive containing what appears to be a common offline utility provided by the department to file tax returns
a malicious DLL ("nvdaHelperRemote.dll"), which, in turn, injects another payload into memory
The end result was an in-memory load of the first binary’s code, which has capabilities to obtain process information and perform injections, specifically process hollowing.
disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine
DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données
Une fois installé sur la machine de la victime, le malware établit une connexion avec un serveur C2, permettant à l’attaquant d’envoyer des instructions et de gérer le système compromis à distance.
343 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
129 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan mentioned as another payload delivered by the group in separate campaigns.
DCRAT4
DCRAT4
A remote access trojan delivered via a multi-stage phishing campaign impersonating the Indian Income Tax Department. In this campaign it is loaded by a .NET malware loader after anti-analysis checks, persistence setup, and AMSI bypass, enabling covert access and data theft from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.