Malware
DCRat
Also known as: DarkCrystal RAT
DCRat is a typical RAT that has been around since at least June 2019.
Indicators of Compromise 14
Domain 6789x[.]site Domain cel-robox[.]com Domain govtop[[.]]one Domain healthymagination[.]com Domain kkxqbh[[.]]top Domain krogeralbertsons[.]com Domain maxfactor-international[.]com Domain rezilion[.]com Domain snsystems[.]com Filename Mixed Reality.exe Filename lllyd.jpg Filename nvdaHelperRemote.dll IP 204[.]194[.]48[.]250 IP 223[.]26[.]63[.]40
MITRE ATT&CK TTPs 18
T1012 T1027 T1036 T1053.003 T1055 T1059 T1070.004 T1071.001 T1082 T1090 T1105 T1190 T1204.002 T1566 T1570 T1583 T1584 T1586
Query Registry
Discovery
Obfuscated Files or Information
Defense Evasion
Masquerading
Defense Evasion
Cron
Execution
Process Injection
Defense Evasion
Command and Scripting Interpreter
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Exploit Public-Facing Application
Initial Access
Malicious File
Execution
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Acquire Infrastructure
Resource Development
Compromise Infrastructure
Resource Development
Compromise Accounts
Resource Development
Source Articles
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.
hacker-news ·2w ago
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat actor is conducting a targeted cyber espionage campaign against Indian taxpayers, tax professionals, and corporate finance teams using spear-phishing emails impersonating the Indian Income Tax Department. The campaign, dubbed Operation DragonReturn, delivers DcRAT via a malicious fake tax filing utility to steal sensitive data and establish persistent access. The attackers use social engineering, DLL side-loading, image-based payload concealment, and Windows service persistence to maintain long-term access to compromised systems.
hacker-news ·1mo ago