DarkTortilla Malware Spread Through Phishing Sites
ID: 4ce292e6-1d86-5ce9-8b03-caeb5f25cd7e
STIX ID: report--4ce292e6-1d86-5ce9-8b03-caeb5f25cd7e
Feed Name: Cyble Blog
This report analyzes an active DarkTortilla malware campaign that uses typosquatted phishing sites (fake Grammarly and Cisco pages) to deliver multi-stage loaders (cabinet/.exe and VC++ binaries) which decrypt and load .NET payloads in memory. The malware performs anti-VM checks, escalates privileges via COM moniker UAC bypass, stores payloads in the registry and LocalAppData, creates scheduled tasks and Run/Startup entries, and modifies Quick Launch .LNK targets to achieve persistence; it also communicates with C2 servers to download additional RATs and stealers. The report includes technical behavior, persistence and evasion details, recommended mitigations, and extensive IoCs (domains, URLs, and file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
