0% found this document useful (0 votes)
25 views17 pages

Understanding Dark Crystal RAT Malware

DARK

Uploaded by

yasmine chiter
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views17 pages

Understanding Dark Crystal RAT Malware

DARK

Uploaded by

yasmine chiter
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Dark Crystal RAT

Remote Access Trojan

Ghettas Houssem Eddine

Bekkouche Fares Lamri


.1introduction
what is DC RAT?
DCRat (DarkCrystal RAT) is a commercial Russian backdoor that was first
released in 2018. has been developed by a single person going by the
pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder.(”
Sold on Russian underground forums, DCRat is one of the cheapest
commercial RATs . The price for this backdoor starts at 500 RUB (6$/ 1200
DA) for a two-month subscription, because of this it’s so popular with
professional threat actors and script kiddies.
.2Define the type of malware
What kind of malware is DarkCrystal?
DC RAT, is a Remote Access Trojan (RAT).
Malware of this type enables remote access
and control over an infected device. RATs
can infiltrate the Windows systems without
users permission and perform several
malicious tasks. This risky Trojan includes
different spiteful symptoms, from info
stealing and tracking to disabling anti-virus.
.3How it infects (attacks)
Malware is proliferated using various techniques .
spam campaigns, illegal activation ("cracking") tools, fake updates and dubious download
channels.
These messages have infectious files attached to and/or linked inside them. Malicious files
can be in various formats (e.g. PDF and Microsoft Office documents, etc.). When they are
executed, run or otherwise opened, the infection chain is triggered illegal activation tools
("cracks") can download / install malware or simply by installing malicious programs rather
than the updates.
Malware disguised as or packed with normal content is often downloaded unintentionally
from untrusted download sources such as unofficial and free file-hosting (freeware) sites,
P2P sharing networks (BitTorrent, Gnutella, eMule, etc.) and other third party downloaders.
.4Who is his target
The primary focus of DCRat is data exfiltration as it supports keylogging as well as
stealing secret information such as credentials from installed web browsers and
FTP clients.

DCRat functions include:

- Keylogging
- Taking screenshots
- Stealing cookies, passwords, and form contents from installed web browsers
- Stealing credentials from installed FTP clients such as FileZilla
- Stealing clipboard contents
- Collecting machine information (host computer name, host username, country
location, installed security products, etc.) and sends the collected information
to a C2 server.

Also, plug-ins are reportedly available to implement additional functionality


depending on the attacker's needs. For example, a recent post on the DCRat's
Telegram channel announced a revamp of a crypto stealer plugin.
.5What is his charge (damage caused)
Cybercriminals use dcRAT for various purposes, such as to:

● Browse the internet by using victims’ machines


● Collect clipboard data
● Collect cookies
● Compile and execute C# code
● Execute remote commands
● Exfiltrate files
● Initialize UDP/TCP flood attacks
● Log keystrokes
● Manage file systems
● Manage running processes
● Turn on webcams and microphones on victims’ machines
● chain infections
● connection to botnet or a cryptocurrency mine
.5how it is detected
By the Symptoms

- Drained CPU performance


- unknown processes running
- strange browser activities
- anti-virus detecting some threats but not able to locate them.
.7How to remove
DarkCrystal removal process is as difficult as any other virus. This can take a long
time to do it manually. This may not even guarantee you complete removal.

Hence, it is advised to scan the infected computer with a reputable anti-malware


software ( we chose SpyHunter ) to detect and remove Dark Crystal Virus.

Steps To Perform System Scan with SpyHunter :


To start the scan click on the “Home” tab and select “Start Scan Now” button. The program
will now start scanning for Dark Crystal and other associated programs.
The scan will report will all the details of the result about DarkCrystal along with system
errors, and malware found.
Once you have found DarkCrystal as shown in the screenshot:
Once you have selected the objects you wish to remove, click the Next button.
.8Finally how to avoid dark crystal rat?
- Do not open spam emails that have any links in them.
- Use only official and verified download sites.
- Avoid illegal activation tools ("crack("
- Perform regular system scans to remove detected or potential threats.

You might also like