ATT&CKSoftwareDarkTortilla

DarkTortilla

S1066

Malware.View on attack.mitre.org

About this malware

DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1007
System Service Discovery

DarkTortilla can retrieve information about a compromised system's running services.

T1016.001
Internet Connection Discovery

DarkTortilla can check for internet connectivity by issuing HTTP GET requests.

T1027
Obfuscated Files or Information

DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators.

T1036
Masquerading

DarkTortilla's payload has been renamed `PowerShellInfo.exe`.

T1047
Windows Management Instrumentation

DarkTortilla can use WMI queries to obtain system information.

T1055.001
Dynamic-link Library Injection

DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection.

T1056.001
Keylogging

DarkTortilla can download a keylogging module.

T1057
Process Discovery

DarkTortilla can enumerate a list of running processes on a compromised system.

T1059.003
Windows Command Shell

DarkTortilla can use `cmd.exe` to add registry keys for persistence.

T1071.001
Web Protocols

DarkTortilla has used HTTP and HTTPS for C2.

T1082
System Information Discovery

DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects.

T1102
Web Service

DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin.

T1105
Ingress Tool Transfer

DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

T1106
Native API

DarkTortilla can use a variety of API calls for persistence and defense evasion.

T1112
Modify Registry

DarkTortilla has modified registry keys for persistence.

View all 28 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Secureworks DarkTortilla Aug 2022 Open source
    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.