DarkWatchMan RAT Spreads Via Phishing Sites
ID: 959a66a6-7efc-5064-a9f2-013ebfa840df
STIX ID: report--959a66a6-7efc-5064-a9f2-013ebfa840df
Feed Name: Cyble Blog
**Executive summary:** Cyble Research identified a phishing site impersonating CryptoPro distributing a DarkWatchman RAT (CSPSetup.exe) that drops a JavaScript RAT and encrypted keylogger, uses the Windows Registry as a fileless storage buffer to evade detection, establishes persistence via scheduled tasks and regsvr32 wrappers, and exfiltrates keystrokes/clipboard/system data to C2; the report includes technical analysis, MITRE ATT&CK mappings, and IOCs (file hashes, filenames, domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
