A phishing campaign is delivering DarkCrystal RAT (DCRat) through weaponized SVG attachments that use HTML smuggling to drop a password-protected 7z archive onto Windows systems. Researchers said the lure impersonates a Colombian legal notice, “Resolución Denuncia Jurídica,” and presents a fake citizen consultation portal that instructs victims to open the downloaded archive with the password 1601, making the staged delivery appear legitimate while shifting malicious assembly into the victim’s browser to evade email inspection.
The attack chain uses double-Base64-encoded JavaScript embedded in the SVG, followed by DLL sideloading with files disguised as Brotli components, persistence through a Windows Registry Run entry, and process hollowing into AddInProcess32.exe. The final payload installs DCRat, a remote access trojan that supports encrypted command-and-control communications, anti-analysis checks, and repeated beaconing to 158[.]94[.]208[.]109, giving attackers sustained access to compromised hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A Gurucul threat research report described the DCRat campaign's use of DLL sideloading, process hollowing, trusted Windows utilities, and in-memory execution after SVG-based phishing. The report also published indicators of compromise including IP address 158.94.208.109 and five file hashes for detection.
In early 2026, Trellix identified a phishing campaign delivering DarkCrystal RAT (DCRat) after investigating a customer escalation. The campaign used SVG attachments with HTML smuggling and legal-notification lures themed as "Resolución Denuncia Jurídica."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcetrellix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.