DCRAT

MITRE ATT&CK: S9017 View on attack.mitre.org

Aliases: DarkCrystal RAT, DCRAT

First seen
2019-06-01 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
windows
Related IoCs
4446 (3597 malicious)
Last IoC activity
2026-09-02 04:29:00
Profile updated
2026-07-07 12:44:57

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

DCRAT is a variant of the open-source AsyncRAT developed in C# with additional capabilities such as patching Microsoft’s Antimalware Scan Interface (AMSI).

Recent IoC activity

3,675 malicious indicators in Maltiverse are attributed to DCRAT (S9017). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname broadres7.duckdns.org 2026-09-03 1
file sample 116ecec88977538ad42809f95bcc003f7e4099dcab5af2884123b6993d378527.bin 2026-09-03 2
hostname onepicce.ydns.eu 2026-09-03 1
IP address 46.246.84.10 2026-09-03 6
file sample 2026-09-02_54e5186ebb256706032b749eabfd6875_drokbk_elex_rhadamanthys_smoke-lo... 2026-09-03 1
IP address 89.163.135.20 2026-09-03 6
hostname itselirose.com 2026-09-03 1
hostname v3.antarcticbiennale.com 2026-09-03 1
hostname xoilactvnn.live 2026-09-03 1
hostname v2.daventryutc.com 2026-09-03 1
hostname xoilac37.run 2026-09-03 1
hostname f1076998.xsph.ru 2026-09-03 1
hostname nitrossites.sa.com 2026-09-03 1
hostname smokeythepurringcat.com 2026-09-03 1
IP address 3.69.115.178 2026-09-03 4
IP address 3.68.171.119 2026-09-03 4
file sample 2026-09-02_5653ec5861b80a5f164954eebf026935_drokbk_elex_rhadamanthys_smoke-lo... 2026-09-03 1
hostname v2.mitvcconference.com 2026-09-03 1
hostname spatang.com 2026-09-03 1
hostname cj79318.tw1.ru 2026-09-03 1

Detection coverage

  • 1 YARA rules
  • 158 Sigma rules

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Keylogging (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Rat_Win_Dcrat_Qwqdanchun (yara-rule)

Reports & references

  • CERT-UA — 405538 (report)
  • botconf.eu — Botconf2022 40 Lunghihorejsi (report)
  • socradar.io — Acuity Federal Breach Okta Leak Dcrat Exploit (report)
  • blogs.blackberry.com — Kraken The Code On Prometheus (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
  • trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • blog.eclecticiq.com — Sandworm Apt Targets Ukrainian Users With Trojanized Microsoft Kms Activation Tools In Cyber Espionage Campaigns (report)
  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • axmahr.github.io — Asyncrat Detection (report)
  • jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
  • recordedfuture.com — Tag 144S Persistent Grip On South American Organizations (report)
  • github.com — Rat King Parser (report)
  • cyber.wtf — Unpacking Pyarmor V8 Scripts (report)
  • redcanary.com — Network Traffic Tunneling (report)
  • kienmanowar.wordpress.com — Quicknote Uncovering Suspected Malware Distributed By Individuals From Vietnam (report)

External references