216.73.217.22

DarkVision RAT

· Published 10/10/2024 16:05 · Modified 11/10/2024 08:10

Export JSON

Essential information

Published
10/10/2024 16:05
Modified
11/10/2024 08:10
Tags
2024-10-10 c2 communication darkvision rat multi-stage attack purecrypter remote access trojan
Related entities
17 techniques (mitre), 2 malware

Description

is a customizable that first appeared in 2020, offered on Hack Forums for $60. Written in C/C++ and assembly, it offers features like keylogging, screenshots, file manipulation, process injection, remote code execution, and password theft. The analysis reveals a chain using as a loader. employs various evasion and privilege escalation techniques, including DLL hijacking and process injection. It communicates with its C2 server using a custom protocol and supports multiple plugins for additional capabilities. The RAT's affordability and extensive feature set make it accessible to low-skilled cybercriminals, posing a significant threat.

External references