logo

DCRat backdoor returns

ID: 7eb79f69-28af-5ba2-8a0f-734a05e2c298

STIX ID: report--7eb79f69-28af-5ba2-8a0f-734a05e2c298

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-03-11

Date Updated: 2026-04-29

Author: AMR

...
...

Kaspersky telemetry describes a current campaign distributing the Dark Crystal RAT (DCRat) via fake or compromised YouTube accounts that link to password‑protected archives; the RAT is sold as Malware‑as‑a‑Service and supports plugins for keylogging, webcam access, file and credential theft, with a large C2 infrastructure using characteristic RU‑zone domain names, primarily affecting users in Russia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.