Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DCRat

14
Global rank
12 infographic chevron month
Month rank
13 infographic chevron week
Week rank
0
IOCs

DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common.

RAT
Type
ex-USSR
Origin
1 July, 2018
First seen
15 September, 2026
Last seen
Also known as
Dark Crystal RAT

How to analyze DCRat with ANY.RUN

RAT
Type
ex-USSR
Origin
1 July, 2018
First seen
15 September, 2026
Last seen

IOCs

IP addresses
107.174.192.179
150.171.28.11
118.194.235.187
208.95.112.1
188.114.96.3
149.154.167.99
104.18.23.222
2.16.204.161
142.251.155.119
142.251.20.132
139.99.85.213
74.178.240.51
154.91.34.165
104.26.12.64
142.250.154.97
172.217.117.4
154.23.184.57
98.177.107.142
23.59.18.102
142.251.14.95
Hashes
74441313bb1fb62500484443c4937e90d4e335351a4fcd12a9ac48448500e33e
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0
4094d158e3b0581ba433a46d0dce62f99d8c0fd1b50bb4d0517ddc0a4a1fde24
99653a38c445ae1d4c373ee672339fd47fd098e0d0ada5f0be70e3b2bf711d38
c158322bd963d2a68ffc878d72213a7394d8c16de72279771ffc924365eec0df
59345c006cd9bde5ef532aae1f119758d45030993181c272bb0dd6fc0c5d01e5
2ae1142b08d296c25000e451237ea919f981da28f6a723d39540f43f18bac762
5639c845d56dedecd2cfdb082b734593b5d618a87f1bd8ec612a8b3f4245566a
32ae9531405ef3c59448fe6dbd3be435e726eb17f3ca0d16530a4c6317dea286
7c68f28c6995f47dd77596bab28c6b4388ff93840c3becfd37733ddb640cd0cd
40cf1af5650b699a947899d2b43a00dcb64cdeaf080651c82a7930910c1c03f4
ec249b0dab6fda20cc24f0f25a504c55a05b23fb6cbb4938aa7a41df0c8744b6
0162159b64eb092f94964faf937f263fb9947b25d40e0d82bd3224d136a140de
77eed9211cd8464482f0da3fac4c0f003c2b8a6d76f15445927e66400f102d60
6558013f984e594bb57534910ce0b17bfa15da3cc9bb4b6e0b5c6e4ddf9eb14e
a7109b8374dffa7a0cd69558990f7e96fea9ef61736d89043dad5a6694cdfa4a
758a0b404b3daadbd0d4e88a0bedf5c21d5507392f7b54d4906ffea49d58ab32
558bbe6193a202dcb00cc441421f5d838764e495b8e4d2e10877db7f661b8cd5
db3ac1fd3d65df45d805adb8dfe0c5209db07ef93406db17dfb783dd8048720a
19acfa0adce363a9c9a3be73f5ec0fac0dcf3c630ce18125fd265040ad6ffb6c
Domains
tpc.googlesyndication.com
api.edgeoffer.microsoft.com
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
static.admaster.cc
msedge.b.tlu.dl.delivery.mp.microsoft.com
identitytoolkit.googleapis.com
lh3.googleusercontent.com
must-directed.gl.at.ply.gg
api.telegram.org
edge.microsoft.com
googleads.g.doubleclick.net
activation-v2.sls.microsoft.com
bucket-cf-weur-a.uploadnow.io
nexusrules.officeapps.live.com
www.bing.com
api.pcloud.com
client.wns.windows.com
slscr.update.microsoft.com
edge-consumer-static.azureedge.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wre-eutrtw_lzyylfryn5gipqsah5d90nzfi4jwh-im&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://uploadnow.io/f/0bcds7g
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://uploadnow.io/en/share?utm_source=0bcds7g
https://cdn.uploadnow.io/_next/static/css/df97d9751ec3abda.css
https://cdn.uploadnow.io/_next/static/css/cda03e3a1ab65c17.css
https://cdn.uploadnow.io/_next/static/css/ae110469aab9e883.css
https://cdn.uploadnow.io/_next/static/css/5ded0d5ca9ecc5c1.css
https://cdn.uploadnow.io/_next/static/chunks/webpack-541c27ed8494cc3b.js
https://cdn.uploadnow.io/_next/static/chunks/framework-b6335179e7eea00c.js
https://cdn.uploadnow.io/_next/static/chunks/main-86f0684c1b20f38d.js
https://cdn.uploadnow.io/_next/static/chunks/pages/_app-a7a0c0b843b84887.js
https://cdn.uploadnow.io/_next/static/chunks/62867-950590631f5ceb03.js
https://cdn.uploadnow.io/_next/static/chunks/38993-a4121c3c0d1b9d33.js
https://cdn.uploadnow.io/_next/static/chunks/41480-7aa8c357827879bd.js
https://cdn.uploadnow.io/_next/static/chunks/3816-6a0007c41b67cb89.js
Last Seen at
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 303
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5151
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10231
comments 0

What is DCRat malware?

DCRat, also known as Dark Crystal RAT, is a remote access trojan (RAT) that lets threat actors take control over an infected machine and extract users’ data, such as the information copied to the clipboard and personal credentials from apps. The malware is known for its stealthiness and its ability to evade detection by security software. DCrat has been in operation since 2018, yet it regularly undergoes changes aimed at advancing and expanding its capabilities.

The malware consists of several components each responsible for a certain type of malicious activity, including stealing of cryptocurrency and keylogging. On top of that, the authors of DCrat have published a special software called DCRat Studio, which serves as a tool for developing new modules for the malware.

DCrat's popularity can be attributed in part to its low cost. Its one-month license goes for a mere $5, while a lifetime one is available for $40. This is a stark contrast to other malware-as-a-service options. For instance, a lifetime AgentTesla subscription will require forking out $120. According to researchers, such prices are due to the malware being simply a pet project of a single developer, who does not work on it full-time. The developer is likely based in the ex-USSR region.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of the DCRat malicious software

Although back in 2018, the malicious program utilized Java, it switched to C# in 2019. As a result, nowadays, the majority of Dark Crystal RAT’s modules are written in the C# programming language. However, the administrative server for this malware is developed with JPHP, which is an implementation of PHP that relies on the Java Virtual Machine.

Different samples of the malware have been observed to be outfitted with evasion and obfuscation techniques. For instance, in order to create a layer of protection against malware analysts’ attempts to reverse engineer its code, DCrat’s payload can be obfuscated with Enigma Protector.

The standard set of tools available to threat actors using DCrat includes:

  • DCRat can record the victim's keystrokes, which can be used to steal passwords and other sensitive information.
  • The separate CryptoStealer module of the malware allows attackers to get access to users’ crypto wallet information.
  • It can collect information about the system (CPU and GPU stats, etc.)
  • It can take screenshots of the victim's computer, which can be used to monitor their activity.
  • DCRat can exfiltrate information from browsers, such as session cookies, auto-fill credentials, and credit card details.
  • The malware can transmit the contents of the victim's clipboard to its command-and-control server (C&C).
  • It can hijack Telegram, Steam, Discord accounts.
  • DCrat can function as a loader, dropping other types of malware on the infected computer.

Additionally, DCrat can execute a persistence algorithm to retain control over the system. For instance, the malware can copy itself to a random running process and to the root directory (C:). It then can create shortcuts to these copies in the user's Startup folder. It can also add registry values that point to these shortcuts. This allows DCrat to start automatically when the computer boots up.

It is important to note that Dark Crystal RAT is polymorphic, meaning that attackers can use its builder functionality to add changes to the malware’s code to make it difficult to detect using traditional methods, such as file hash.

Execution process of DCRat

Uploading Dark Crystal RAT to the ANY.RUN sandbox lets you quickly see the malicious activities triggered by the malware. Here is a sample of DCrat executed in the interactive sandbox.

DCrat's flexibility makes it challenging to handle, but there are things that can help us pinpoint it. For example, DCrat rarely produces malicious activity in its current process. Like most malware, it prefers to create large process trees and then infiltrate a harmless process at some point to detonate later. By using ANY.RUN, we can easily identify the process targeted by the malware.

DCRat process tree DCRat's process tree

On top of that, it can delay execution for a period of time after the infection, drop executables, run embedded payloads, and use WMI queries to detect a virtualized environment or or to gain persistence in the system.

DCRat process tree DCRat's WMI queries

Distribution methods of the DCRat malware

Since Dark Crystal RAT is sold openly on the Internet, cyber criminals of all skill levels have access to it. Subsequently, there are many different methods they implement to drop the payload on victims’ computers. Yet, as is the case with most remote access trojans, including Vidar, njRAT, and QuasarRAT, DCrat’s main way of infecting a system is via phishing emails.

Threat actors devise sophisticated multi-staged attacks intended to manipulate the victim into believing that the fake email is actually legitimate and the attachment file it contains is safe to open. These downloadable files are usually in an office suite format, such as .docx or .xls, and have built-in macros or other mechanisms that can trigger the chain reaction which will result in DCRat being dropped onto the system.

There are also accounts of users unsuspectingly downloading a DCrat executable from websites distributing torrent files. In such cases, the malware can be disguised as a legitimate program. Once executed, the program installs the malicious program and runs it, stealing the user’s data often without them being aware of it.

Conclusion

Dark Crystal RAT is a remote access trojan that constitutes a significant concern for organizations and individuals worldwide. The malware’s low price tag and modular design make it an in-demand tool among cyber criminals. To protect your system from DCrat, you should be very careful about opening links or attachments from unknown senders.

Instead of taking the risk of downloading and opening potentially harmful files or clicking on malicious links, you can first analyze them in a sandbox environment like ANY.RUN. This will allow you to quickly and safely determine whether the file is malicious or not. ANY.RUN will also provide you with a detailed report about the malware, including its indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). This information can be used to protect your organization from future attacks.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More
SalatStealer screenshot
SalatStealer
salatstealer
SalatStealer, also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
Read More
Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More