DCRat backdoor returns
ID: 7eb79f69-28af-5ba2-8a0f-734a05e2c298
STIX ID: report--7eb79f69-28af-5ba2-8a0f-734a05e2c298
Feed Name: Securelist by Kaspersky
Threat Score
Kaspersky telemetry describes a current campaign distributing the Dark Crystal RAT (DCRat) via fake or compromised YouTube accounts that link to password‑protected archives; the RAT is sold as Malware‑as‑a‑Service and supports plugins for keylogging, webcam access, file and credential theft, with a large C2 infrastructure using characteristic RU‑zone domain names, primarily affecting users in Russia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
