DcRAT is a remote access trojan used in the Operation DragonReturn campaign to steal sensitive data from compromised hosts. It is delivered via a multi-stage attack chain involving DLL side-loading, image-based payload concealment, and Windows service persistence.