Threat Advisory

PureCrypter Distributes DarkVision RAT to Target Systems in Malware Campaign

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

DarkVision RAT is a highly customizable remote access trojan (RAT) that emerged in gaining traction for its extensive feature set and adaptability. This malware, written in C/C++ and assembly, is accessible to a wide range. DarkVision RAT includes capabilities such as keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. It has been observed operating in conjunction with PureCrypter, further enhancing its distribution and evasion techniques.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

DarkVision RAT is a highly customizable remote access trojan (RAT) that emerged in gaining traction for its extensive feature set and adaptability. This malware, written in C/C++ and assembly, is accessible to a wide range. DarkVision RAT includes capabilities such as keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. It has been observed operating in conjunction with PureCrypter, further enhancing its distribution and evasion techniques.[emaillocker id="1283"]

The attack chain behind DarkVision RAT infections begins with a .NET executable that decrypts a second-stage shellcode using Triple Data Encryption Standard (3DES). This shellcode is a Donut loader, which loads DarkVision RAT's payload from a .NET assembly called PureCrypter. The RAT employs various evasion techniques, including adding exclusions to Windows Defender and implementing multiple persistence methods such as autorun keys and task scheduling. DarkVision RAT communicates with its command-and-control (C2) server using a custom binary protocol, allowing it to receive commands and exfiltrate data. It uses a unique Bot ID for registration, followed by a series of ACK packets for command acknowledgment, leading to the execution of its malicious functions.

In conclusion, DarkVision RAT exemplifies a versatile and potent tool, offering a wide range of capabilities that make it a significant threat. Its ease of use and adaptability, combined with effective evasion tactics and communication protocols, contribute to its growing popularity among attackers. It should remain vigilant and implement robust security measures to detect and mitigate the risks posed by this evolving malware.

THREAT PROFILE:

Tactic Technique Id Technique
 Execution T1053 Scheduled Task/Job
Persistence T1547 Boot or Logon Autostart Execution
 Defense Evasion T1055 Process Injection
T1140 Deobfuscate/Decode Files or Information
T1562 Impair Defenses
Credential Access T1539 Steal Web Session Cookie
 Discovery T1010 Application Window Discovery
T1057 Process Discovery
T1082 System Information Discovery
T1083 File and Directory Discovery
Collection T1123 Audio Capture
T1125 Video Capture
T1113 Screen Capture
T1056 Input Capture
Command and Control T1219 Remote Access Software
T1571 Non-Standard Port
 Impact T1529 System Shutdown/Reboot

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/10/new-malware-campaign-uses-purecrypter.html

[/emaillocker]
crossmenu