Darksky

First seen
2018-03-01 00:00:00
Malware type
botnet, ddos, downloader, cryptominer
Family
Malware family
Profile updated
2026-07-07 14:56:47

Targeted industries: financial-services technology-and-telecommunications

Context

DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed denial-of-service (DDoS) attacks, and detecting and evading security controls, such as sandboxes and virtual machines. It is advertised for sale on the dark web for $20. Much of the malware that DarkSky has available to download onto targeted systems is associated with cryptocurrency-mining activity. The DDoS attacks that DarkSky can perform include DNS amplification attacks, TCP (SYN) flood, UDP flood, and HTTP flood. The botnet can also perform a check to determine whether or not the DDoS attack succeeded and turn infected systems into a SOCKS/HTTP proxy to route traffic to a remote server.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Darktrackrat (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Darksky (report)
  • blog.radware.com — Darksky Botnet (report)
  • telegra.ph — Analiz Botneta Darksky 12 30 (report)

External references