DarkTortilla

MITRE ATT&CK: S1066 View on attack.mitre.org

Aliases: DarkTortilla

First seen
2015-08-01 00:00:00
Malware type
loader, trojan
Family
Malware family
Operating systems
windows
Related IoCs
395 (393 malicious)
Last IoC activity
2026-09-01 23:56:54
Profile updated
2026-07-07 14:43:17

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

Recent IoC activity

394 malicious indicators in Maltiverse are attributed to DarkTortilla (S1066). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample PO-110592021.exe 2026-09-02 1
file sample 6ba3976f8956dceb2903dc89b9b66c3d81ceb93566b6244b58c4929a454815c0 2026-09-01 2
file sample invoice and packing list.exe 2026-09-01 1
file sample invoice and packing list.exe 2026-08-31 2
file sample invoice and packing list.exe 2026-08-31 2
file sample CH2.exe 2026-08-31 3
file sample sub_f3df175fa985.bin 2026-08-29 4
file sample MBSetup.exe 2026-08-29 1
file sample IMPORT_PO2024-0961_ASTG.7z.rar 2026-08-28 2
file sample 4a13cc6df28d860cdc90acd79d6c7f48225afbec160de4cd7d805c262310b983 2026-08-25 2
file sample 61b9f5a1e4ef18ed559b55f51d5c17b51c90c9a75fb5f6523b6243ae2f5bf70c 2026-08-25 2
file sample 5b79bb5c716c9797e048785965be3c3a54a73a587d23d0027130cb31b618e124 2026-08-25 2
file sample 444a717c2a081ef2a4f3fb5995644893c2a00431723a9119391c790684c40b5a 2026-08-25 2
file sample _05e47adb0cfea5580dda196cfff46275ea9e3445ad55cbc2c850bac5ae4cbb42.exe 2026-08-24 3
file sample wfwf.exe 2026-08-23 2
file sample confirm POF.exe 2026-08-23 2
file sample PAYMENT_.EXE 2026-08-23 4
file sample 342b9b062a450358374c5f29f89ba2433f4fffadbfb350dca4080484fb727576 2026-08-22 2
file sample 489ccd9807e0c63e43cbbec56ed0043151fc47cf84cde1e5dd405ecd4d1fdd6f 2026-08-21 2
file sample DrawingXspecificationXandXJuneXPOX#07329.tar 2026-08-21 2

Detection coverage

  • 583 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Winlogon Helper DLL (attack-pattern)
  • Time Based Checks (attack-pattern)
  • COR_PROFILER (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Masquerading (attack-pattern)
  • Hide Artifacts (attack-pattern)
  • System Checks (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Keylogging (attack-pattern)
  • Malicious File (attack-pattern)
  • Process Discovery (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Native API (attack-pattern)
  • Web Service (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Component Object Model (attack-pattern)

Reports & references

  • secureworks.com — Darktortilla Malware Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Darktortilla (report)
  • MITRE ATT&CK — S1066 (report)

External references