WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness - DarkTortilla Malware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – DarkTortilla Malware

Author: Alec Davison

Created: Thursday, August 18, 2022 - 19:26

Categories: Cybersecurity

Security researchers are warning defenders to be aware of ‘DarkTortilla’ which several threat actors are using to deliver a wide range of information stealers, remote-access Trojans (RATs), and other malicious payloads. DarkTortilla was first observed by researchers in October 2021, but they believe it has been active since at least 2015. Similar to other malware, threat actors are distributing DarkTortilla via spam emails with file attachments such as .ISO, .ZIP, and .IMG. In some instances, they have also used malicious documents to deliver the malware. DarkTortilla is a highly modular crypter, which is software designed to help malware remain undetected through bypassing anti-malware and anti-sandbox tools to maintain persistence and load additional malicious payloads. DarkTortilla also employs social engineering techniques including displaying fake messages on victim devices designed to trick users into believing the malware executing on their system is benign. Read more at DarkReading.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Active Exploitation of Check Point VPN Authentication Bypass Vulnerability, CVE-2026-50751

Jun 10, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q2 2026

Jun 10, 2026 in Cybersecurity, Federal & State Resources, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar