logo

DarkTortilla Malware: How It Works and How to Test Your Defenses

ID: 8494dc68-591e-5780-9332-4eb0e1b0f7ea

STIX ID: report--8494dc68-591e-5780-9332-4eb0e1b0f7ea

Feed Name: Picus Security Articles

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

Author: [email protected] (Umut Bayram)

...
...

**DarkTortilla** is a sophisticated .NET-based crypter and multi-stage loader used since at least 2015 that spreads via logistics-themed phishing attachments (e.g., .iso, .zip, .img) and hides encrypted configuration inside bitmap images; it fetches or embeds a core processor DLL, decrypts it (Rijndael/ECB with a fixed key), and injects popular payloads (AgentTesla, AsyncRat, RedLine, Cobalt Strike, etc.) into legitimate processes for in-memory execution while employing persistence (HKCU Run, hidden shell, Startup .lnk), anti-analysis checks, execution delays, and a WatchDog mechanism to maintain/recover components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.