DCRat backdoor returns
#1
Bug 
Quote:Since the beginning of the year, we’ve been tracking in our telemetry a new wave of DCRat distribution, with paid access to the backdoor provided under the Malware-as-a-Service (MaaS) model. The cybercriminal group behind it also offers support for the malware and infrastructure setup for hosting the C2 servers.

Distribution

The DCRat backdoor is distributed through the YouTube platform. Attackers create fake accounts or use stolen ones, then upload videos advertising cheats, cracks, gaming bots and similar software. In the video description is a download link to the product supposedly being advertised. The link points to a legitimate file-sharing service where a password-protected archive awaits, the password for which is also in the video description.

[Image: DarkCrystal_RAT_01-740x1024.png]
YouTube video ad for a cheat and crack

Instead of gaming software, these archives contain the DCRat Trojan, along with various junk files and folders to distract the victim’s attention.

[Image: DarkCrystal_RAT_02-1024x1001.png]Archives with DCRat disguised as a cheat and crack

Backdoor

The distributed backdoor belongs to a family of remote access Trojans (RATs) dubbed Dark Crystal RAT (DCRat for short), known since 2018. Besides backdoor capability, the Trojan can load extra modules to boost its functionality. Throughout the backdoor’s existence, we have obtained and analyzed 34 different plugins, the most dangerous functions of which are keystroke logging, webcam access, file grabbing and password exfiltration.

Continue Reading...
Reply


Messages In This Thread
DCRat backdoor returns - by harlan4096 - Yesterday, 11:30

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Privazer 4.0.19
PrivaZer  v4.0.103...Kool — 11:50
XYplorer
What's new in Rele...Kool — 11:46
DCRat backdoor returns
Since the beginnin...harlan4096 — 11:30
Mozilla Firefox Browser 136.0.1
Mozilla Firefox Br...harlan4096 — 10:28
Google Chrome 134.0.6998.88/.89
Google Chrome 134....harlan4096 — 10:18

[-]
Birthdays
Today's Birthdays
avatar (41)napasvem
avatar (43)diploJeoca
Upcoming Birthdays
avatar (43)gapedDow
avatar (37)snorydar
avatar (42)Hectorvot
avatar (50)knowhanPluts
avatar (38)Williamengiz
avatar (45)qaqapeti
avatar (43)battsourIonix
avatar (42)CedricSek
avatar (38)chasRex
avatar (50)tersfargum
avatar (49)alfreExept
avatar (32)uteluxix
avatar (46)piafcflene
avatar (38)Matthewkah
avatar (37)Charlesfibre
avatar (37)francisnj3
avatar (42)artmaGoork
avatar (40)RichardCisee

[-]
Online Staff
There are no staff members currently online.

>