Darksky
- First seen
- 2018-03-01 00:00:00
- Malware type
- botnet, ddos, downloader, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:56:47
Targeted industries: financial-services technology-and-telecommunications
Context
DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed denial-of-service (DDoS) attacks, and detecting and evading security controls, such as sandboxes and virtual machines. It is advertised for sale on the dark web for $20. Much of the malware that DarkSky has available to download onto targeted systems is associated with cryptocurrency-mining activity. The DDoS attacks that DarkSky can perform include DNS amplification attacks, TCP (SYN) flood, UDP flood, and HTTP flood. The botnet can also perform a check to determine whether or not the DDoS attack succeeded and turn infected systems into a SOCKS/HTTP proxy to route traffic to a remote server.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Darktrackrat (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Darksky (report)
- blog.radware.com — Darksky Botnet (report)
- telegra.ph — Analiz Botneta Darksky 12 30 (report)