Skip to content
Threat Feed
medium advisory

DCRat Forkbomb Payload Activity

The DCRat malware utilizes a forkbomb technique, spawning rapid, high-volume processes of cmd.exe and notepad.exe to induce system instability and resource exhaustion.

DCRat, a known Remote Access Trojan (RAT), employs a destructive 'forkbomb' payload mechanism designed to compromise system stability. The threat actor leverages this technique to spawn a rapid succession of cmd.exe instances, which in turn launch numerous notepad.exe processes. This activity creates severe resource exhaustion, leading to potential denial of service or total system disruption. The behavior is typically initiated by a batch script execution. Defenders should monitor for high-frequency process creation patterns within a short time window (30 seconds) to identify potential DCRat infections in the environment. This technique is observed as part of the malware's post-exploitation capability to destabilize the target host.

Attack Chain

  1. Malware or an initial loader drops a malicious batch file onto the target Windows host.
  2. The batch file is executed via a command shell, creating a parent cmd.exe process.
  3. The batch script logic triggers an iterative loop to spawn multiple child processes.
  4. Each iteration of the loop invokes a new cmd.exe instance.
  5. Each cmd.exe instance launches an instance of notepad.exe.
  6. The rapid, concurrent creation of 10 or more process pairs (cmd.exe -> notepad.exe) consumes system CPU and memory resources.
  7. The system reaches a state of instability or performance degradation due to the forkbomb effect.

Impact

Successful execution of this forkbomb payload leads to significant resource exhaustion, rendering the affected system unresponsive or unstable. This technique effectively disrupts legitimate services and can be used to prevent administrative access or security tool intervention during an ongoing intrusion, impacting productivity and system availability.

Recommendation

  • Deploy the Sigma rule below to detect rapid process creation patterns indicative of a forkbomb.
  • Enable Sysmon Event ID 1 (Process Creation) logging across all endpoints to capture process lineage and command-line arguments.
  • Configure EDR telemetry to ingest full process metadata, including process GUID and parent-child relationships, to facilitate the detection of rapid process spawning.
  • Prioritize investigation of alerts identifying 10 or more cmd.exe to notepad.exe process pairs within a 30-second interval.

Immediate actions

Deploy Sigma rule and enable threshold-based alerting for cmd.exe/notepad.exe forkbombs

Detection Engineering 24h

Threat Hunt

Search for high-frequency process launches of notepad.exe spawned by cmd.exe

T1059.003 high high confidence hunt now

Data: Sysmon Event ID 1 logs

Detection coverage 1

Detect DCRat Forkbomb Process Activity

high

Detects the rapid creation of cmd.exe processes spawning notepad.exe, which is indicative of a DCRat forkbomb payload.

sigma tactics: execution techniques: T1059.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →