DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least 2015 and targeting Windows systems. It is commonly delivered through logistics-themed spearphishing emails carrying malicious documents, archives, or disk-image attachments that require user interaction. The loader decrypts its core components and runtime configuration in memory, including configuration data concealed in bitmap pixel data, and can retrieve additional components from public paste services.
DarkTortilla supports in-memory payload execution through process injection and has delivered Agent Tesla, AsyncRAT, NanoCore, RedLine, Cobalt Strike, and Metasploit. Its modular architecture can download supplemental payloads, including clipboard-stealing and keylogging modules, as well as other malware, miners, legitimate executables, and decoy documents.
The malware implements configurable persistence through user-level autorun settings, modified logon shell settings, and Startup-folder shortcuts. A mutually monitored watchdog and loader recovery mechanism can restore terminated components, reapply persistence, and reinject payloads. Defense-evasion features include code, string, control-flow, and configuration obfuscation; virtual-machine, debugger, profiler, security-software, process, and service checks; execution delays; payload execution without writing the main payload to disk; and fake error messages. It also uses WMI to collect host information and can test outbound internet connectivity before continuing execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples include "DarkTortilla can obtain system information by querying the Win32_ComputerSystem, Win32_BIOS, Win32_MotherboardDevice, Win32_PnPEntity, and Win32_DiskDrive WMI objects" and "Kimsuky has also obtained system information ... through querying various Windows Management Instrumentation (WMI) classes including Win32_OperatingSystem."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
“With standard registry persistence, the core processor adds the installed loader to HKCU\Software\Microsoft\Windows\CurrentVersion\Run... The core processor can also create a .lnk shortcut in the Startup folder.”
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
“With standard registry persistence, the core processor adds the installed loader to HKCU\Software\Microsoft\Windows\CurrentVersion\Run... The core processor can also create a .lnk shortcut in the Startup folder.”
“The loader replaces meaningful code names with obscure identifiers and uses switch statements to control execution.”
“DarkTortilla stores its encrypted configuration inside bitmap images embedded in the loader.”
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
“The core processor decrypts the configuration with the RijndaelManaged cryptographic class and a fixed 16-byte key.”
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
“The core processor queries system information through WMI and examines running processes and services.”
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
“The %VM% configuration field enables virtual-machine checks. The core processor queries system information through WMI and examines running processes and services. If it finds virtual-machine indicators, it terminates the loader.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows-focused .NET crypter and multistage loader delivered through phishing attachments. It conceals encrypted configuration data in bitmap pixels, retrieves or loads a core processor DLL in memory, establishes registry or Startup-folder persistence, and injects payloads into legitimate processes. It includes anti-analysis checks, execution delays, fake errors, payload reinjection, and a mutually monitoring WatchDog recovery component.
A .NET-based crypter and loader used to distribute and execute next-stage malware payloads, such as Formbook, often employing obfuscation and evasion techniques.
Modular .NET loader used in malspam-driven infection chains to deploy commodity malware. In this campaign, a 32-bit VB.NET executable (QNaZg.exe) decrypts an embedded DLL using a reverse+conditional XOR routine and reflectively loads it into memory, then uses .NET reflection/late binding to invoke the payload.
A loader that checks for internet connectivity via HTTP GET requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.