logo

DCRat Malware Hits Windows with Remote Access, Keylogging, Screen Capture, and File Theft Capabilities

ID: 5b29f1b3-8437-5801-bb38-2b611fdfa3e1

STIX ID: report--5b29f1b3-8437-5801-bb38-2b611fdfa3e1

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-07-02

Date Updated: 2026-04-19

Author: Mandvi

...
...

**Executive Summary:** A targeted phishing campaign is deploying the modular DCRat RAT against Windows users (predominantly in Colombia) via password-protected ZIPs that execute obfuscated scripts which retrieve a steganography-embedded payload; the malware supports modular plugins, credential harvesting, keylogging, persistence, and remote control. The report includes anti-analysis details (virtual machine checks, AMSI bypass), full attack chain description, and multiple IoCs (paste URLs, image archive, SHA-256 hashes, and a C2 IP), and notes that Fortinet products can detect and block the threat when signatures and engines are current.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.