Malware.View on attack.mitre.org
DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
DarkTortilla can retrieve information about a compromised system's running services. |
| T1016.001 Internet Connection Discovery |
DarkTortilla can check for internet connectivity by issuing HTTP GET requests. |
| T1027 Obfuscated Files or Information |
DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators. |
| T1036 Masquerading |
DarkTortilla's payload has been renamed `PowerShellInfo.exe`. |
| T1047 Windows Management Instrumentation |
DarkTortilla can use WMI queries to obtain system information. |
| T1055.001 Dynamic-link Library Injection |
DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection. |
| T1056.001 Keylogging |
DarkTortilla can download a keylogging module. |
| T1057 Process Discovery |
DarkTortilla can enumerate a list of running processes on a compromised system. |
| T1059.003 Windows Command Shell |
DarkTortilla can use `cmd.exe` to add registry keys for persistence. |
| T1071.001 Web Protocols |
DarkTortilla has used HTTP and HTTPS for C2. |
| T1082 System Information Discovery |
DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects. |
| T1102 Web Service |
DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin. |
| T1105 Ingress Tool Transfer |
DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit. |
| T1106 Native API |
DarkTortilla can use a variety of API calls for persistence and defense evasion. |
| T1112 Modify Registry |
DarkTortilla has modified registry keys for persistence. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.