DarkWatchman Malware Carries RAT and Keylogger Features

Cybersecurity experts are reporting of a new piece of malware by the name DarkWatchman. This project appears to be written in a JavaScript, and its features are typical for a Remote Access Trojan (RAT.) One of this threat's quirks is its ability to utilize the Windows Registry in order to store various configuration and data, enabling the malware to leave minimum footprint on the victim's hard drive.

The fileless execution capability of the DarkWatchman Malware is not to be underestimated. Thanks to it, the malware could be able to bypass tons of security measures since it does not really drop any files onto the victim's disk. In addition to this, it uses an advanced domain generation algorithm (DGA) to determine its command-and-control server and contact it.

The first victims of the DarkWatchman Malware to be identified were major companies operating in Russia. However, there are no indications that the DarkWatchman Malware is part of a state-sponsored attack campaign. The strange part is that the DarkWatchman Malware implant was not used to steal data or cause major issues. This might mean that the criminals are using it for reconnaissance, and they might be planning to introduce a secondary payload in the future. This is a common strategy that major ransomware gangs employ in order to maximize their success.

In addition to the RAT functionality, the DarkWatchman Malware also boasts a keylogger module written in C#. The criminals are likely to adapt their malware propagation strategy according to their victim's profile. For example, Russian companies were contacted via a fake email from a real shipment company. Fileless malware like DarkWatchman can go a long way because of its evasive properties. We are yet to see how far this particular campaign will spread.

December 17, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.