DcRAT (Dark Crystal RAT) is a .NET-based Malware-as-a-Service remote access trojan that has been active since 2018 (originally Java, redesigned in C# in 2019). Priced at just $5-7 for a two-month license, it offers 34 plugins, a dedicated IDE for custom plugin development, and has been deployed by threat actors including UAC-0200 against Ukrainian defense infrastructure.
Overview & MaaS Model
DcRAT stands out in the RAT ecosystem for its remarkably low price point and comprehensive feature set. While NjRAT relies on source code availability and Cobalt Strike on cracked copies, DcRAT offers a fully supported commercial MaaS platform at a fraction of competitors' prices.
DcRAT's pricing makes it accessible to virtually any threat actor: $5 for 2 months, $7 for a year, or a lifetime license for a small additional fee. This is dramatically cheaper than alternatives like Warzone RAT ($38/month) or legitimate tools like Cobalt Strike ($5,900/year).
- Platform: .NET Framework (C#); server, client, and plugin IDE all .NET-based
- Sales channel: Russian-language cybercrime forums; Telegram; dedicated website (crystalfiles.ru, previously)
- Support: Active Telegram support channel; regular updates; changelog published
- Licensing: Server-side license check; operators cannot redistribute without authorization
Developer Profile
DcRAT is developed and maintained by a single Russian individual using the handle "boldenis44" (also "crystalcoder"). Unlike many MaaS operations run by organized groups, DcRAT appears to be a one-person project — which introduces both unpredictability and a single point of failure.
- Active since: 2018 (Java version), 2019 (C# rewrite)
- Communications: Russian-language forums and Telegram
- Development pace: Regular updates; responsive to customer feedback
- Russian authorities: In 2024, Russian law enforcement blocked 110+ domains associated with DcRAT distribution
Architecture & Plugin Ecosystem
Components
- DcRAT Server: .NET WinForms application for managing infected hosts, issuing commands, viewing data
- DcRAT Client: Configurable .NET payload generated via the server's builder
- DCLIB IDE: Dedicated Visual Studio-like IDE for developing custom DcRAT plugins in C#
Plugin Ecosystem (34 Plugins)
| Category | Plugins | Capabilities |
|---|---|---|
| Surveillance | Keylogger, Webcam, Microphone, Screenshots | Full victim monitoring suite |
| Credential Theft | BrowserStealer, CookieStealer, PasswordStealer | Browser data extraction |
| Crypto | CryptoStealer, ClipboardHijacker | Wallet theft and clipboard address swapping |
| Ransomware | FileEncryptor | AES file encryption with ransom note |
| Evasion | AntiVM, ProcessKiller, DisableDefender | Security tool neutralization |
| Persistence | StartupManager, TaskScheduler, RegistryPersist | Multiple persistence mechanisms |
| Networking | ReverseProxy, SOCKS5, PortForward | Network pivoting capabilities |
| System | FileManager, ProcessManager, ServiceManager | Remote system administration |
Technical Analysis
Execution Chain
- Delivery: Typically arrives as obfuscated .NET executable, often via dropper chain T1204.002
- Obfuscation: Uses .NET obfuscators (ConfuserEx, custom packers) to evade static analysis T1027.002
- Persistence: Registry Run keys, scheduled tasks, or startup folder placement T1547.001
- Plugin loading: Dynamically loads plugins from C2 server based on operator commands
- Data exfiltration: Stolen data sent to C2 server via TCP connection T1041
C2 Protocol
- Protocol: Custom TCP protocol with AES encryption T1573.001
- Authentication: Client authenticates with server using embedded credentials
- Commands: Plugin deployment, file operations, shell commands, configuration updates
- Heartbeat: Regular keep-alive packets to maintain connection state
Distribution Methods
YouTube Campaigns (2025)
In 2025, DcRAT distribution campaigns heavily leveraged YouTube, using AI-generated video content promoting fake game cheats, cracked software, and cryptocurrency tools. Links in video descriptions lead to DcRAT-infected downloads.
- YouTube videos: AI-generated tutorials for game cheats and cracked software with malicious download links
- Phishing emails: Targeted emails with DcRAT payloads disguised as business documents T1566.001
- Signal messaging: UAC-0200 distributes via compromised Signal accounts targeting Ukrainian military T1566.002
- Trojanized software: Bundled with legitimate-looking applications and tools
Threat Actor Usage
| Threat Actor | Region | Target | Context |
|---|---|---|---|
| UAC-0200 | Russia-aligned | Ukrainian Defense Forces | Distributed via Signal messages to military personnel; espionage operations |
| NyashTeam | Russia | Ukraine, opposition | Pro-Russian hacktivist group using DcRAT for surveillance |
| BlindEagle (APT-C-36) | Latin America | Colombian financial sector | Financial espionage using DcRAT alongside other tools |
| Script kiddies | Global | Various | Low-cost entry point for unsophisticated attackers |
UAC-0200's use of DcRAT against Ukrainian Defense Forces via Signal messaging represents a significant escalation in the use of commodity malware in active conflict zones. The low cost and commercial support make DcRAT attractive for intelligence operations where operational security matters less than speed of deployment.
MITRE ATT&CK Mapping
| Tactic | Technique | Usage |
|---|---|---|
| Execution | T1204.002 Malicious File | User executes disguised .NET payload |
| Persistence | T1547.001 Registry Run Keys | Registry-based autostart |
| Defense Evasion | T1027.002 Software Packing | ConfuserEx and custom .NET obfuscation |
| Defense Evasion | T1562.001 Disable Security Tools | DisableDefender plugin |
| Credential Access | T1056.001 Keylogging | Keylogger plugin |
| Credential Access | T1555.003 Browser Credentials | BrowserStealer plugin |
| Collection | T1125 Video Capture | Webcam surveillance plugin |
| Collection | T1115 Clipboard Data | ClipboardHijacker for crypto addresses |
| Exfiltration | T1041 Exfil Over C2 | All data via encrypted C2 channel |
| C2 | T1573.001 Encrypted Channel | AES-encrypted TCP protocol |
Detection & Defense
- .NET analysis: Monitor for obfuscated .NET executables running from temp/appdata directories
- Plugin loading detection: Alert on .NET assemblies dynamically loaded from network sources
- Clipboard monitoring: Detect crypto address swapping by monitoring clipboard changes for wallet address patterns
- Network signatures: DcRAT's TCP protocol has identifiable handshake and authentication patterns
- YouTube link monitoring: Block or warn on downloads from YouTube video description links (especially game cheats)
- YARA rules: Available from BlackBerry, CERT-UA, and community researchers
- Defender tampering alerts: Critical to alert on any attempts to disable Windows Defender
- Signal security: Train personnel to verify Signal message sources, especially those containing file attachments
Defend Against MaaS RAT Threats
Mjolnir Security provides comprehensive detection and response capabilities against DcRAT and the broader MaaS RAT ecosystem.
- MaaS RAT Detection Behavioral detection of DcRAT plugin loading, credential theft, and clipboard hijacking activity within your environment.
- Conflict Zone Threat Intelligence Specialized intelligence on threat actors targeting organizations in active conflict zones, including UAC-0200 TTPs and Signal-based delivery vectors.
- 24/7 Incident Response Rapid containment and forensic investigation when RAT activity is detected. Call +1 833 403 5875.
Stay ahead of emerging threats. Get notified when we publish new intelligence reports and advisories.
Subscribe to Alerts