logo

DCRat Targets Users with HTML Smuggling

ID: 5bebf133-cc5a-5917-9cf5-0a4b171bce12

STIX ID: report--5bebf133-cc5a-5917-9cf5-0a4b171bce12

Feed Name: Netskope Threat Labs

Threat Score
65/100

Date Published: 2024-09-26

Date Updated: 2026-04-28

Author: Nikhil Hegde

...
...

Netskope analyzed a campaign delivering DCRat (Dark Crystal RAT) using HTML smuggling to drop a password-protected ZIP that contained nested RarSFX archives which ultimately executed DCRat binaries (packed with ENIGMA/VMProtect). The report describes the full execution chain, evasion techniques (HTML smuggling, password-protected archives, packing), related detections, MITRE ATT&CK mappings, provided IOCs and scripts on GitHub, and recommended mitigations such as full HTTP/HTTPS inspection and remote browser isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.