DC RAT is a Windows remote access trojan used to provide unauthorized control of infected systems. It is commonly observed as a commodity RAT delivered in multi-stage malware campaigns alongside other stealers and remote administration malware. Reported delivery chains include phishing-themed lures using weaponized Office documents, malicious SVG attachments, and archive files containing shortcut or script-based launchers, with subsequent stages relying on obfuscated scripting, in-memory loading, and process hollowing to deploy the final payload.
DC RAT is associated with post-compromise remote control activity on victim hosts and has been seen in campaigns targeting manufacturing and government organizations, including victims in Europe and the Middle East. It is also referenced in underground and tutorial ecosystems alongside other commodity RAT families, indicating accessibility to a broad range of criminal operators rather than exclusive use by a single threat actor.
High-confidence reporting supports DC RAT as part of intrusion chains that use defense-evasion techniques during delivery, including obfuscation, steganographic payload concealment, hidden PowerShell execution, and process injection into legitimate Windows processes. In observed campaigns, DC RAT functions as one of several interchangeable final-stage payloads selected by operators depending on operational goals. Its role is consistent with remote access, hands-on-keyboard follow-on activity, and broader post-exploitation operations on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote Access Trojan (RAT) used for persistent access and control over infected systems.
Remote Access Trojan (RAT) delivered via commodity loader, used for remote control and data exfiltration.
Mentioned only as another RAT referenced in tutorial videos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.