DarkTortilla Malware: How It Works and How to Test Your Defenses
ID: 8494dc68-591e-5780-9332-4eb0e1b0f7ea
STIX ID: report--8494dc68-591e-5780-9332-4eb0e1b0f7ea
Feed Name: Picus Security Articles
**DarkTortilla** is a sophisticated .NET-based crypter and multi-stage loader used since at least 2015 that spreads via logistics-themed phishing attachments (e.g., .iso, .zip, .img) and hides encrypted configuration inside bitmap images; it fetches or embeds a core processor DLL, decrypts it (Rijndael/ECB with a fixed key), and injects popular payloads (AgentTesla, AsyncRat, RedLine, Cobalt Strike, etc.) into legitimate processes for in-memory execution while employing persistence (HKCU Run, hidden shell, Startup .lnk), anti-analysis checks, execution delays, and a WatchDog mechanism to maintain/recover components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
