DarkEye
- First seen
- 2017-05-12 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-05-24 01:59:07
- Profile updated
- 2026-07-07 14:56:22
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
DarkEye is a sophisticated remote access trojan (RAT) primarily used for cyber-espionage. It has been detected targeting various sectors, including government and financial services, with capabilities to exfiltrate sensitive data and control infected systems remotely.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Darkeye (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Darkeye (yara-rule)
Related threat objects
- Prynt Stealer (malware)
- WorldWind (malware)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Darkeye (report)
- zscaler.com — No Honor Among Thieves Prynt Stealers Backdoor Exposed (report)