Backdoor.DCRat

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Backdoor.DCRat is Malwarebytes’ detection name for all the variants of a specific backdoor which is for sale one the Dark Web.

Type of infection

A backdoor is a type of Trojan that allows a threat actor access to a system by bypassing its security. Backdoor.DCRat is a cheap yet versatile Trojan that can provide the operator with informarion about almost everything the user of the affected device does after infection. This includes taking screenshots, keylogging, and stealing passwords.

Backdoor.DCRat can be bought from the author via the Dark Web and the developers’ Telegram channel.

Protection

Malwarebytes blocks Backdoor.DCRat by using real-time protection.

Malwarebytes blocks Backdoor.DCRat
Malwarebytes blocks Backdoor.DCRat

Business remediation

How to remove Backdoor.DCRat with the Malwarebytes Nebula console

You can use the Malwarebytes Anti-Malware Nebula console to scan endpoints.

endpoint menu

Nebula endpoint tasks menu

Choose the Scan + Quarantine option. Afterwards you can check the Detections page to see which threats were found.On the Quarantine page you can see which threats were quarantined and restore them if necessary.

Home remediation

Malwarebytes can detect and remove Backdoor.DCRat without further user interaction.