DarkTortilla Malware: How It Works and How to Test Your Defenses
Brief
Key Takeaways
- DarkTortilla is a highly configurable .NET crypter and multi-stage loader active since at least August 2015.
- Logistics-themed phishing emails deliver the loader inside archive and disk-image attachments such as .iso, .zip, and .img.
- Encrypted configuration hides inside embedded bitmap images, decrypted with Rijndael in ECB mode using a fixed key.
- Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk.
- The Picus Platform simulates DarkTortilla malware attacks so teams can validate security controls against this threat.
DarkTortilla is a highly configurable . NET-based crypter and multi-stage loader active since at least August 2015. It targets Windows systems, spreading through logistics-themed phishing emails.
DarkTortilla Malware: How It Works and How to Test Your Defenses
