Executive Summary
DarkTortilla is a sophisticated .NET crypter that encrypts and delivers multiple payloads—including information stealers and RATs—while evading traditional detection. First observed in 2015, it has served as an obfuscation layer for a wide range of ransomware and exfiltration tools, complicating incident response efforts.
Enhanced Description
DarkTortilla is a highly configurable .NET-based crypter that has been active since at least August 2015, according to Secureworks analysis. It functions as an obfuscation layer that packages malicious payloads in strongly encrypted executables, thereby evading signature‑based detection and complicating static analysis. The tool is routinely used by threat actors to deliver a diverse array of threats—including popular information stealers (Agent Tesla), RAT frameworks (AsyncRat, NanoCore, RedLine, Cobalt Strike), and exploitation tools such as Metasploit. Once deployed, DarkTortilla typically extracts the embedded payload to a temporary folder where it launches the secondary malware. The crypter supports multi‑layer encryption schemes that can be customized per delivery, making it a preferred choice for supply‑chain attacks or phishing campaigns seeking high stealth. Its reliance on .NET also allows leverage of legitimate Windows components and scripting environments (e.g., PowerShell) to carry out post‑infection tasks. The impact of DarkTortilla lies in its role as a facilitator: by masking the true nature of payloads, it enables attackers to increase persistence, expand lateral movement, and exfiltrate data without raising immediate suspicion. Security teams should treat any unknown .NET executable with embedded encrypted content as high‑risk, especially if accompanied by suspicious network behavior or unfamiliar registry keys.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly cited Secureworks reports and observed associations between DarkTortilla and various known malware families, providing moderate confidence in its capabilities. However, exact encryption schemes, command‑and‑control protocols, and potential supply‑chain integration details remain unspecified.
DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.(Citation: Secureworks DarkTortilla Aug 2022)