The .NET-based malware DarkTortilla has recently been observed in active campaigns by researchers from Cyble Research and Intelligence Labs (CRIL). Various stealers and Remote Access Trojans (RATs) are being used along with DarkTortilla, including AgentTesla, AsyncRAT, NanoCore, and others. DarkTortilla has been operating in various capacities since 2015. The threat actors behind this most recent campaign have created phishing sites that mirror the legitimate pages for Grammarly and Cisco. The malicious links are being distributed via spam emails or various online ads. Once users visit these sites, the infection of DarkTortilla begins if malicious samples are downloaded.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security