logo

DarkTortilla Malware Spread Through Phishing Sites

ID: 4ce292e6-1d86-5ce9-8b03-caeb5f25cd7e

STIX ID: report--4ce292e6-1d86-5ce9-8b03-caeb5f25cd7e

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-07-20

...
...

This report analyzes an active DarkTortilla malware campaign that uses typosquatted phishing sites (fake Grammarly and Cisco pages) to deliver multi-stage loaders (cabinet/.exe and VC++ binaries) which decrypt and load .NET payloads in memory. The malware performs anti-VM checks, escalates privileges via COM moniker UAC bypass, stores payloads in the registry and LocalAppData, creates scheduled tasks and Run/Startup entries, and modifies Quick Launch .LNK targets to achieve persistence; it also communicates with C2 servers to download additional RATs and stealers. The report includes technical behavior, persistence and evasion details, recommended mitigations, and extensive IoCs (domains, URLs, and file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.