DCRAT
MITRE ATT&CK: S9017 View on attack.mitre.org
Aliases: DarkCrystal RAT, DCRAT
- First seen
- 2019-06-01 00:00:00
- Malware type
- rat, spyware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4446 (3597 malicious)
- Last IoC activity
- 2026-09-02 04:29:00
- Profile updated
- 2026-07-07 12:44:57
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
DCRAT is a variant of the open-source AsyncRAT developed in C# with additional capabilities such as patching Microsoft’s Antimalware Scan Interface (AMSI).
Recent IoC activity
3,675 malicious indicators in Maltiverse are attributed to DCRAT (S9017). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | broadres7.duckdns.org | 2026-09-03 | 1 |
| file sample | 116ecec88977538ad42809f95bcc003f7e4099dcab5af2884123b6993d378527.bin | 2026-09-03 | 2 |
| hostname | onepicce.ydns.eu | 2026-09-03 | 1 |
| IP address | 46.246.84.10 | 2026-09-03 | 6 |
| file sample | 2026-09-02_54e5186ebb256706032b749eabfd6875_drokbk_elex_rhadamanthys_smoke-lo... | 2026-09-03 | 1 |
| IP address | 89.163.135.20 | 2026-09-03 | 6 |
| hostname | itselirose.com | 2026-09-03 | 1 |
| hostname | v3.antarcticbiennale.com | 2026-09-03 | 1 |
| hostname | xoilactvnn.live | 2026-09-03 | 1 |
| hostname | v2.daventryutc.com | 2026-09-03 | 1 |
| hostname | xoilac37.run | 2026-09-03 | 1 |
| hostname | f1076998.xsph.ru | 2026-09-03 | 1 |
| hostname | nitrossites.sa.com | 2026-09-03 | 1 |
| hostname | smokeythepurringcat.com | 2026-09-03 | 1 |
| IP address | 3.69.115.178 | 2026-09-03 | 4 |
| IP address | 3.68.171.119 | 2026-09-03 | 4 |
| file sample | 2026-09-02_5653ec5861b80a5f164954eebf026935_drokbk_elex_rhadamanthys_smoke-lo... | 2026-09-03 | 1 |
| hostname | v2.mitvcconference.com | 2026-09-03 | 1 |
| hostname | spatang.com | 2026-09-03 | 1 |
| hostname | cj79318.tw1.ru | 2026-09-03 | 1 |
Detection coverage
- 1 YARA rules
- 158 Sigma rules
Malware & tools used
- Asymmetric Cryptography (attack-pattern)
- Keylogging (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Disable or Modify Tools (attack-pattern)
Used by threat actors
- APT-C-36 (threat-actor)
Detection rules
- SEKOIA_Rat_Win_Dcrat_Qwqdanchun (yara-rule)
Reports & references
- CERT-UA — 405538 (report)
- botconf.eu — Botconf2022 40 Lunghihorejsi (report)
- socradar.io — Acuity Federal Breach Okta Leak Dcrat Exploit (report)
- blogs.blackberry.com — Kraken The Code On Prometheus (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- blog.eclecticiq.com — Sandworm Apt Targets Ukrainian Users With Trojanized Microsoft Kms Activation Tools In Cyber Espionage Campaigns (report)
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- axmahr.github.io — Asyncrat Detection (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
- github.com — Rat King Parser (report)
- cyber.wtf — Unpacking Pyarmor V8 Scripts (report)
- redcanary.com — Network Traffic Tunneling (report)
- kienmanowar.wordpress.com — Quicknote Uncovering Suspected Malware Distributed By Individuals From Vietnam (report)