EXECUTIVE SUMMARY
DarkVision RAT is a highly customizable remote access trojan (RAT) that emerged in gaining traction for its extensive feature set and adaptability. This malware, written in C/C++ and assembly, is accessible to a wide range. DarkVision RAT includes capabilities such as keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. It has been observed operating in conjunction with PureCrypter, further enhancing its distribution and evasion techniques.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
DarkVision RAT is a highly customizable remote access trojan (RAT) that emerged in gaining traction for its extensive feature set and adaptability. This malware, written in C/C++ and assembly, is accessible to a wide range. DarkVision RAT includes capabilities such as keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. It has been observed operating in conjunction with PureCrypter, further enhancing its distribution and evasion techniques.[emaillocker id="1283"]
The attack chain behind DarkVision RAT infections begins with a .NET executable that decrypts a second-stage shellcode using Triple Data Encryption Standard (3DES). This shellcode is a Donut loader, which loads DarkVision RAT's payload from a .NET assembly called PureCrypter. The RAT employs various evasion techniques, including adding exclusions to Windows Defender and implementing multiple persistence methods such as autorun keys and task scheduling. DarkVision RAT communicates with its command-and-control (C2) server using a custom binary protocol, allowing it to receive commands and exfiltrate data. It uses a unique Bot ID for registration, followed by a series of ACK packets for command acknowledgment, leading to the execution of its malicious functions.
In conclusion, DarkVision RAT exemplifies a versatile and potent tool, offering a wide range of capabilities that make it a significant threat. Its ease of use and adaptability, combined with effective evasion tactics and communication protocols, contribute to its growing popularity among attackers. It should remain vigilant and implement robust security measures to detect and mitigate the risks posed by this evolving malware.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1053 | Scheduled Task/Job |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1055 | Process Injection |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1562 | Impair Defenses | |
| Credential Access | T1539 | Steal Web Session Cookie |
| Discovery | T1010 | Application Window Discovery |
| T1057 | Process Discovery | |
| T1082 | System Information Discovery | |
| T1083 | File and Directory Discovery | |
| Collection | T1123 | Audio Capture |
| T1125 | Video Capture | |
| T1113 | Screen Capture | |
| T1056 | Input Capture | |
| Command and Control | T1219 | Remote Access Software |
| T1571 | Non-Standard Port | |
| Impact | T1529 | System Shutdown/Reboot |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/10/new-malware-campaign-uses-purecrypter.html