Malware
DarkTortilla
DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015.
DarkTortilla is a Windows malware family.
Background
DarkTortilla is an intricate and highly configurable .NET crypter that may have been in use since at least August 2015. It commonly drops well-known information stealers and remote access trojans (RATs) including AgentTesla, AsyncRat, NanoCore, and RedLine. Although it mostly distributes commodity malware, Secureworks® Counter Threat Unit™ (CTU) researchers found DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit, and it can additionally deploy "addon packages" comprising further malicious payloads, harmless decoy documents, and executables. Its strong anti-analysis and anti-tamper defenses can hamper detection, analysis, and removal.
Between January 2021 and May 2022, roughly 93 unique DarkTortilla samples were submitted to VirusTotal each week on average. Shared code points to possible ties between DarkTortilla and other malware: a crypter run by the RATs Crew threat group, active from 2008 to 2012, and the Gameloader malware that appeared in 2021.
Source: Malpedia (Fraunhofer FKIE).