DCRAT
DARK CRYSTAL
MAAS RAT
UAC-0200
Threat IntelligenceMalwareAPTDecember 3, 202515 min read

DcRAT: The Budget MaaS RAT Targeting Ukraine and Beyond

Inside the $5/month Malware-as-a-Service RAT built by a solo Russian developer — with 34 plugins, a dedicated IDE, and deployment against Ukrainian defense infrastructure by multiple threat groups.

Scroll

DcRAT (Dark Crystal RAT) is a .NET-based Malware-as-a-Service remote access trojan that has been active since 2018 (originally Java, redesigned in C# in 2019). Priced at just $5-7 for a two-month license, it offers 34 plugins, a dedicated IDE for custom plugin development, and has been deployed by threat actors including UAC-0200 against Ukrainian defense infrastructure.

Overview & MaaS Model

DcRAT stands out in the RAT ecosystem for its remarkably low price point and comprehensive feature set. While NjRAT relies on source code availability and Cobalt Strike on cracked copies, DcRAT offers a fully supported commercial MaaS platform at a fraction of competitors' prices.

Pricing Model

DcRAT's pricing makes it accessible to virtually any threat actor: $5 for 2 months, $7 for a year, or a lifetime license for a small additional fee. This is dramatically cheaper than alternatives like Warzone RAT ($38/month) or legitimate tools like Cobalt Strike ($5,900/year).

Developer Profile

Solo Developer

DcRAT is developed and maintained by a single Russian individual using the handle "boldenis44" (also "crystalcoder"). Unlike many MaaS operations run by organized groups, DcRAT appears to be a one-person project — which introduces both unpredictability and a single point of failure.

Architecture & Plugin Ecosystem

Components

Plugin Ecosystem (34 Plugins)

CategoryPluginsCapabilities
SurveillanceKeylogger, Webcam, Microphone, ScreenshotsFull victim monitoring suite
Credential TheftBrowserStealer, CookieStealer, PasswordStealerBrowser data extraction
CryptoCryptoStealer, ClipboardHijackerWallet theft and clipboard address swapping
RansomwareFileEncryptorAES file encryption with ransom note
EvasionAntiVM, ProcessKiller, DisableDefenderSecurity tool neutralization
PersistenceStartupManager, TaskScheduler, RegistryPersistMultiple persistence mechanisms
NetworkingReverseProxy, SOCKS5, PortForwardNetwork pivoting capabilities
SystemFileManager, ProcessManager, ServiceManagerRemote system administration

Technical Analysis

Execution Chain

C2 Protocol

Distribution Methods

YouTube Campaigns (2025)

Social Engineering

In 2025, DcRAT distribution campaigns heavily leveraged YouTube, using AI-generated video content promoting fake game cheats, cracked software, and cryptocurrency tools. Links in video descriptions lead to DcRAT-infected downloads.

Threat Actor Usage

Threat ActorRegionTargetContext
UAC-0200Russia-alignedUkrainian Defense ForcesDistributed via Signal messages to military personnel; espionage operations
NyashTeamRussiaUkraine, oppositionPro-Russian hacktivist group using DcRAT for surveillance
BlindEagle (APT-C-36)Latin AmericaColombian financial sectorFinancial espionage using DcRAT alongside other tools
Script kiddiesGlobalVariousLow-cost entry point for unsophisticated attackers
Conflict Zone Deployment

UAC-0200's use of DcRAT against Ukrainian Defense Forces via Signal messaging represents a significant escalation in the use of commodity malware in active conflict zones. The low cost and commercial support make DcRAT attractive for intelligence operations where operational security matters less than speed of deployment.

MITRE ATT&CK Mapping

TacticTechniqueUsage
ExecutionT1204.002 Malicious FileUser executes disguised .NET payload
PersistenceT1547.001 Registry Run KeysRegistry-based autostart
Defense EvasionT1027.002 Software PackingConfuserEx and custom .NET obfuscation
Defense EvasionT1562.001 Disable Security ToolsDisableDefender plugin
Credential AccessT1056.001 KeyloggingKeylogger plugin
Credential AccessT1555.003 Browser CredentialsBrowserStealer plugin
CollectionT1125 Video CaptureWebcam surveillance plugin
CollectionT1115 Clipboard DataClipboardHijacker for crypto addresses
ExfiltrationT1041 Exfil Over C2All data via encrypted C2 channel
C2T1573.001 Encrypted ChannelAES-encrypted TCP protocol

Detection & Defense

Defend Against MaaS RAT Threats

Mjolnir Security provides comprehensive detection and response capabilities against DcRAT and the broader MaaS RAT ecosystem.

RAT DetectionThreat HuntingIncident ResponseMDR ServicesSecurity AwarenessDark Web Intelligence
  • MaaS RAT Detection Behavioral detection of DcRAT plugin loading, credential theft, and clipboard hijacking activity within your environment.
  • Conflict Zone Threat Intelligence Specialized intelligence on threat actors targeting organizations in active conflict zones, including UAC-0200 TTPs and Signal-based delivery vectors.
  • 24/7 Incident Response Rapid containment and forensic investigation when RAT activity is detected. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: December 3, 2025