Signed, Sealed, Injected: The Mechanics of DCRat in 2026

    Date: 08/17/2026

    Severity: High

    Summary

    This DCRat campaign combines phishing with SVG attachment, DLL sideloading, and process hollowing to establish stealthy remote access while evading endpoint defenses. By abusing trusted Windows utilities and requiring user interaction, the malware blends into legitimate activity and enables in-memory execution. The campaign highlights the importance of threat hunting, module load monitoring, network correlation, and patch management to detect modern malware delivery techniques. 

    Indicators of Compromise (IOC) List

    IP Address

    158.94.208.109

    Hash

    F205AB7E6AEFC10B9833D1A9A91BAD02

    A3A471F1C7A605DD34AF49EF075E1251

    13df3e065c421436bf0ac6fed3f9bb7f

    d4bb45d3aef7a9161df4cadaeeba6a39

    Acef69c68b8c3d3c3e1e53196a26ca60

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("158.94.208.109") or srcipaddress IN ("158.94.208.109")

    Detection Query 2 :

    md5hash IN ("d4bb45d3aef7a9161df4cadaeeba6a39","F205AB7E6AEFC10B9833D1A9A91BAD02","Acef69c68b8c3d3c3e1e53196a26ca60","13df3e065c421436bf0ac6fed3f9bb7f","A3A471F1C7A605DD34AF49EF075E1251")

    Reference: 

    https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/         


    Tags

    MalwareDCRATPhishingSVGDLLSideLoadingRAT

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags