DarkTortilla
MITRE ATT&CK: S1066 View on attack.mitre.org
Aliases: DarkTortilla
- First seen
- 2015-08-01 00:00:00
- Malware type
- loader, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 395 (393 malicious)
- Last IoC activity
- 2026-09-01 23:56:54
- Profile updated
- 2026-07-07 14:43:17
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.
Recent IoC activity
394 malicious indicators in Maltiverse are attributed to DarkTortilla (S1066). The 20 most recently updated:
Detection coverage
- 583 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Winlogon Helper DLL (attack-pattern)
- Time Based Checks (attack-pattern)
- COR_PROFILER (attack-pattern)
- Security Software Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Masquerading (attack-pattern)
- Hide Artifacts (attack-pattern)
- System Checks (attack-pattern)
- Clipboard Data (attack-pattern)
- Keylogging (attack-pattern)
- Malicious File (attack-pattern)
- Process Discovery (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Native API (attack-pattern)
- Web Service (attack-pattern)
- System Service Discovery (attack-pattern)
- Component Object Model (attack-pattern)
Reports & references
- secureworks.com — Darktortilla Malware Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Darktortilla (report)
- MITRE ATT&CK — S1066 (report)