DCRat, also known as DarkCrystal RAT, is a Windows .NET remote-access trojan derived from AsyncRAT source code. It provides attackers with remote control of compromised hosts and uses encrypted TLS command-and-control communications; implementations have used AsyncRAT-style certificate validation and certificate pinning. DCRat clients can delay execution, apply anti-analysis checks, enforce single-instance execution, bypass AMSI, and establish Windows persistence. Observed delivery chains have used phishing, including judicial and government-themed lures, malicious SVG attachments employing HTML smuggling, weaponized Office documents exploiting CVE-2017-11882, and multi-stage script loaders. Campaigns have used DLL sideloading and process hollowing to execute DCRat within legitimate Windows processes and evade endpoint defenses. DCRat has been observed in campaigns targeting Colombian organizations and in operations targeting Indian and Afghan government, diplomatic, and related entities. It has also appeared in phishing ecosystems assessed as consistent with Blind Eagle tradecraft, although such campaign-level associations do not establish exclusive attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office... A typical infection would consist of a malicious document, such as an RTF file exploiting CVE-2017-11882, a stack overflow vulnerability that enables arbitrary code execution on a vulnerable version of Microsoft Office. | These attacks use dcRAT and QuasarRAT for Windows delivered via malicious documents exploiting CVE-2017-11882.
Associated Analytic Story ... DarkCrystal RAT
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
CERT-UA received information about targeted cyberattacks against Ukrainian civil servants, military personnel, and representatives of defense enterprises using the DarkCrystal RAT malware, which is distributed via the Signal messenger.
DcRat est un cheval de Troie d'accès à distance (RAT) identifié principalement en association avec le groupe de menaces RedFoxtrot. DcRat est conçu pour permettre aux attaquants de prendre le contrôle à distance des systèmes infectés et est généralement utilisé pour le vol de données, la surveillance et le déploiement de logiciels malveillants supplémentaires.
...the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat.
AsyncRAT (racine) → DCRAT (DarkCrystal RAT, descendant le plus prolifique)
28 distinct techniques documented for this family, organized by ATT&CK tactic.
This DCRat campaign combines phishing with SVG attachment, DLL sideloading, and process hollowing to establish stealthy remote access while evading endpoint defenses.
By abusing trusted Windows utilities and requiring user interaction, the malware blends into legitimate activity and enables in-memory execution.
A fake CAPTCHA lure led to a PowerShell based loader... The loader ultimately delivered the DCRat remote access trojan.
After execution, a folder is created in the user directory, inside it is dropping selfcopy with its dependency DLLs and a batch script.
Upon inspecting the source code, we discovered an embedded JavaScript script containing double Base64-encoded content... It then saves the file as 'DOC-16-ENE-2026 RESOLUCION DENUNCIA JURIDICA.7z' in the user’s downloads folder.
The payload starts a legitimate process, “AddInProcess32.exe,” in a suspended state using CreateProcessInternalW. It then manipulates the thread’s registers with Wow64GetThreadContext and Wow64SetThreadContext, and injects its malicious code into the target process’s memory using WriteProcessMemory.
This is a classic example of HTML Smuggling... the script includes function code to decode the content and uses a Blob function to reconstruct a ZIP file entirely in the browser's memory.
The nature of malware communications with its C&C server(s) has advanced over time, from using plain non-encrypted channels to using custom and standard symmetric ... and asymmetric ... encryption algorithms and protocols (SSL/TLS) to hinder network inspection of such malicious traffic.
The decoy loader pretends to be a genuine program but intentionally includes malicious DLLs... using Brotli-style names helps the malware blend in and look harmless at first glance.
Finally, ResumeThread restarts the process, which now runs the attacker’s code while appearing to be a normal Windows executable.
It begins by decoding a Base64-encoded key, which is then used to set up AES-256 decryption. Through this process, multiple hidden settings are unlocked.
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
After configuring buffer sizes and creating a TCP socket, it chooses the server’s host and port either by retrieving them from a Pastebin link or by selecting at random from a list of predefined values.
“Related samples contacted code repositories and cloud storage” and “The operation can move files between familiar services.”
463 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
181 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access malware found among the recovered operator artifacts, indicating the campaign operators could rotate among multiple RAT payloads.
A remote-access trojan included among the operator's recovered RAT build inventory and referenced by a C2 hostname naming convention.
Remote-access trojan delivered through an AI-assisted-looking PowerShell loader distributed via a fake CAPTCHA lure.
Remote access trojan observed among malware samples contacting Sable Squirrel-operated dropcatch domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.