DarkTortilla is a Windows malware family/loader distributed primarily through spearphishing emails containing archive attachments such as .iso, .zip, .img, .dmg, and .tar, as well as malicious documents. Initial execution relies on user interaction to open the malicious document or archived file delivered via email. Observed capabilities include persistence through registry key modification and creation of a .lnk shortcut in the Windows Startup folder via the WshShortcut COM object; system discovery using WMI queries to obtain system information; retrieval of information about running services; security software discovery, including checks for Kaspersky Anti-Virus; internet connectivity checks via HTTP GET requests; retrieval of its primary payload from public sites such as Pastebin and Textbin; modular payload delivery including clipboard information stealer and keylogging modules; process injection using a .NET-based DLL named RunPe6; and anti-analysis checks that detect debuggers using DebuggerIsAttached and DebuggerIsLogging and detect profilers by verifying whether the COR_ENABLE_PROFILING environment variable is present and active. A reported masquerading behavior is renaming its payload to PowerShellInfo.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
Examples include "DarkTortilla can obtain system information by querying the Win32_ComputerSystem, Win32_BIOS, Win32_MotherboardDevice, Win32_PnPEntity, and Win32_DiskDrive WMI objects" and "Kimsuky has also obtained system information ... through querying various Windows Management Instrumentation (WMI) classes including Win32_OperatingSystem."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
Examples include: 'APT28 has deployed malware that has copied itself to the startup directory for persistence' and 'APT29 added Registry Run keys to establish persistence.'
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
Multiple actors and malware check for internet/network connectivity using ping, tracert, HTTP GET requests, or contacting well-known domains (e.g., google[.]com, bing[.]com, 8.8.8.8) prior to tool transfer or C2 establishment.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
“APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads… EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads… Bumblebee has been downloaded… from OneDrive… Operation Spalax… used OneDrive and MediaFire to host payloads… Raspberry Robin… payloads… on Discord servers.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based crypter and loader used to distribute and execute next-stage malware payloads, such as Formbook, often employing obfuscation and evasion techniques.
Modular .NET loader used in malspam-driven infection chains to deploy commodity malware. In this campaign, a 32-bit VB.NET executable (QNaZg.exe) decrypts an embedded DLL using a reverse+conditional XOR routine and reflectively loads it into memory, then uses .NET reflection/late binding to invoke the payload.
A loader that checks for internet connectivity via HTTP GET requests.
Malware delivered via malicious documents or archives sent by email.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.