← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 11, 2026 · 12:25via Malware.news

DarkTortilla Malware: How It Works and How to Test Your Defenses

Brief

Key Takeaways

  • DarkTortilla is a highly configurable .NET crypter and multi-stage loader active since at least August 2015.
  • Logistics-themed phishing emails deliver the loader inside archive and disk-image attachments such as .iso, .zip, and .img.
  • Encrypted configuration hides inside embedded bitmap images, decrypted with Rijndael in ECB mode using a fixed key.
  • Main payloads including AgentTesla, AsyncRat, RedLine, and Cobalt Strike run injected in memory, never touching disk.
  • The Picus Platform simulates DarkTortilla malware attacks so teams can validate security controls against this threat.

DarkTortilla is a highly configurable . NET-based crypter and multi-stage loader active since at least August 2015. It targets Windows systems, spreading through logistics-themed phishing emails.

DarkTortilla Malware: How It Works and How to Test Your Defenses

Read more on Malware.news→