DarkWatchman
MITRE ATT&CK: S0673 View on attack.mitre.org
Aliases: DarkWatchman
- First seen
- 2021-11-01 00:00:00
- Malware type
- rat, keylogger
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 823 (822 malicious)
- Last IoC activity
- 2026-09-01 20:32:36
- Profile updated
- 2026-07-07 13:16:16
Targeted industries: financial-services technology-and-telecommunications
Context
DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.
Recent IoC activity
823 malicious indicators in Maltiverse are attributed to DarkWatchman (S0673). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | 4ad74aab.shop | 2026-09-03 | 1 |
| hostname | 4ad74aab.fun | 2026-09-03 | 1 |
| IP address | 31.56.48.238 | 2026-09-02 | 1 |
| hostname | d27ef8b8.store | 2026-08-30 | 1 |
| hostname | f45848da.store | 2026-08-28 | 1 |
| hostname | 791688a4.space | 2026-08-28 | 1 |
| hostname | db49f51f.shop | 2026-08-27 | 1 |
| file sample | 2bcc8e7439a0170a9adb90d9deeec8675027ac39509a8aea8494700abbdb37b8 | 2026-08-24 | 4 |
| hostname | fa059aab.space | 2026-08-19 | 1 |
| hostname | fd835c2d.shop | 2026-08-18 | 1 |
| hostname | 27dd67e8.biz.ua | 2026-08-18 | 1 |
| file sample | ÐÑполниÑелÑнÑй лиÑÑ â13408724-25.scr | 2026-08-18 | 2 |
| hostname | fa629f23.fun | 2026-08-17 | 1 |
| hostname | fa2b8b86.online | 2026-08-16 | 1 |
| file sample | 3f99c6b90b7488d59d17adcd1b6fde61752ab3709533f34a5d9eaafcb0fe412e.exe | 2026-08-16 | 2 |
| hostname | f752ebbd.store | 2026-08-16 | 1 |
| hostname | fc16d578.space | 2026-08-16 | 1 |
| hostname | fbd691cb.space | 2026-08-16 | 1 |
| hostname | fe9a381a.shop | 2026-08-15 | 1 |
| hostname | f45848da.space | 2026-08-14 | 1 |
Detection coverage
- 690 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Fileless Storage (attack-pattern)
- Compression (attack-pattern)
- Modify Registry (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Application Window Discovery (attack-pattern)
- PowerShell (attack-pattern)
- System Time Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Command Obfuscation (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Query Registry (attack-pattern)
- Shared Modules (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Command Shell (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Compile After Delivery (attack-pattern)
- Scheduled Task (attack-pattern)
Reports & references
- securityintelligence.com — Hive00117 Fileless Malware Delivery Eastern Europe (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Darkwatchman (report)
- cyble.com — Sophisticated Darkwatchman Rat Spreads Through Phishing Sites (report)
- intrinsec.com — Intrinsec 2025 Threat Report Trouble In The Air (report)
- securityintelligence.com — New Hive0117 Phishing Campaign Imitates Conscription Summons Deliver Darkwatchman Malware (report)
- prevailion.com — Darkwatchman New Fileness Techniques (report)
- MITRE ATT&CK — S0673 (report)
- web.archive.org — Darkwatchman New Fileless Techniques (report)