Introduction
In early 2026, the
Trellix Advanced Research Center (ARC) identified and analyzed an active DarkCrystal RAT (DCRat) campaign following a critical customer escalation. The operation relied on a judicial‑themed phishing lure, masquerading as an official
“Resolución Denuncia Jurídica” (legal complaint resolution) to pressure victims into opening the attachment. Every stage of the attack required human interaction, from opening the phishing email to extracting the archive to executing the malicious components alongside trusted libraries by using DLL sideloading. In its final stage, the malware employed process hollowing to inject malicious code into a trusted system process, effectively evading detection. The end payload was DCRat, granting attackers full remote access and control. This campaign is particularly notable for legitimate, signed utility to bypass traditional security perimeters.
This blog unpacks each stage of the infection chain, revealing how attackers combine stealth, sideloading, and process injection to establish long‑term access.
Here is a refined, explanatory breakdown of the infection chain identified by Trellix ARC.
Attack kill chain