Description
DarkTortilla is a highly configurable .NET based crypter that has possibly been active since August 2015. It delivers information stealers, remote access trojans, and other payloads such as Agent Tesla, AsyncRAT, NanoCore, RedLine, Cobalt Strike, and Metasploit.
Stats
- First seen
- February 2023
- Last seen
- October 2026
Also known as
Darktortilla
MITRE ATT&CK techniques
28 techniques across 8 tactics.
TA0002 Execution
TA0003 Persistence
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
TA0112 Defense Impairment
- T1112Modify Registry
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Darktortilla |
| ByteCode-MSIL.Trojan.DarkTortilla |
| Gen:Variant.Cerbu.DarkTortilla.134368 |
| Win32.Exploit.DarkTortilla |
| Win32.Ransomware.DarkTortilla |
| Win32.Spyware.DarkTortilla |
| Win32.Trojan.DarkTortilla |