DarkWatchman

MITRE ATT&CK: S0673 View on attack.mitre.org

Aliases: DarkWatchman

First seen
2021-11-01 00:00:00
Malware type
rat, keylogger
Family
Malware family
Operating systems
windows
Related IoCs
823 (822 malicious)
Last IoC activity
2026-09-01 20:32:36
Profile updated
2026-07-07 13:16:16

Targeted industries: financial-services technology-and-telecommunications

Context

DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.

Recent IoC activity

823 malicious indicators in Maltiverse are attributed to DarkWatchman (S0673). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname 4ad74aab.shop 2026-09-03 1
hostname 4ad74aab.fun 2026-09-03 1
IP address 31.56.48.238 2026-09-02 1
hostname d27ef8b8.store 2026-08-30 1
hostname f45848da.store 2026-08-28 1
hostname 791688a4.space 2026-08-28 1
hostname db49f51f.shop 2026-08-27 1
file sample 2bcc8e7439a0170a9adb90d9deeec8675027ac39509a8aea8494700abbdb37b8 2026-08-24 4
hostname fa059aab.space 2026-08-19 1
hostname fd835c2d.shop 2026-08-18 1
hostname 27dd67e8.biz.ua 2026-08-18 1
file sample Исполнительный лист №13408724-25.scr 2026-08-18 2
hostname fa629f23.fun 2026-08-17 1
hostname fa2b8b86.online 2026-08-16 1
file sample 3f99c6b90b7488d59d17adcd1b6fde61752ab3709533f34a5d9eaafcb0fe412e.exe 2026-08-16 2
hostname f752ebbd.store 2026-08-16 1
hostname fc16d578.space 2026-08-16 1
hostname fbd691cb.space 2026-08-16 1
hostname fe9a381a.shop 2026-08-15 1
hostname f45848da.space 2026-08-14 1

Detection coverage

  • 690 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Compression (attack-pattern)
  • Modify Registry (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • System Time Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Query Registry (attack-pattern)
  • Shared Modules (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Scheduled Task (attack-pattern)

Reports & references

  • securityintelligence.com — Hive00117 Fileless Malware Delivery Eastern Europe (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Darkwatchman (report)
  • cyble.com — Sophisticated Darkwatchman Rat Spreads Through Phishing Sites (report)
  • intrinsec.com — Intrinsec 2025 Threat Report Trouble In The Air (report)
  • securityintelligence.com — New Hive0117 Phishing Campaign Imitates Conscription Summons Deliver Darkwatchman Malware (report)
  • prevailion.com — Darkwatchman New Fileness Techniques (report)
  • MITRE ATT&CK — S0673 (report)
  • web.archive.org — Darkwatchman New Fileless Techniques (report)

External references