DarkVision RAT
ID: 25f4d42f-46ec-5f5e-b36e-42d4b0f016d6
STIX ID: report--25f4d42f-46ec-5f5e-b36e-42d4b0f016d6
Feed Name: Zscaler Security Research Blog
This technical analysis describes a multi‑stage campaign that delivers DarkVision RAT, detailing each stage from a .NET droppers and 3DES‑encrypted shellcode through a Donut loader and PureCrypter injector to the final RAT. The report covers persistence and evasion (Windows Defender exclusions, autorun/task scheduler/startup folder, registry storage), process injection via section mapping, a custom C2 protocol and registration/fingerprinting flow, supported remote commands and a broad plugin set (webcam, keylogger, password theft, VNC/hVNC, file operations, remote shell), and includes IOCs such as file paths, sample GUID usages and an example C2 host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
