Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
DarkWatchman is a modular, fileless-style Windows remote-access trojan associated with the financially motivated Hive0117 intrusion set, also tracked as Watch Wolf, Ratopak Spider, and UAC-0008.
Profile source: Mallory opens in a new tabDarkWatchman
DarkWatchman is a modular, fileless-style Windows remote-access trojan associated with the financially motivated Hive0117 intrusion set, also tracked as Watch Wolf, Ratopak Spider, and UAC-0008. First observed in 2021, it has primarily targeted Russian organizations, particularly accounting and financial staff, to facilitate fraud involving corporate remote-banking systems. It has also been observed in campaigns against Russian aerospace and defense-adjacent entities.
DarkWatchman uses obfuscated JavaScript executed through Windows Script Host and PowerShell components, including an encrypted PowerShell keylogger. It uses the Windows Registry to store configuration, payload data, keylogging output, and locally staged collected data, minimizing disk-resident artifacts. Persistence is established through a scheduled task, and installation artifacts and temporary keylogger material are removed after deployment. The malware can compile a C# executable with the .NET C# compiler after delivery.
Its collection functions include keystrokes, clipboard contents, smart-card-reader information, system and host details, usernames, operating-system locale, and installed security-product information. DarkWatchman can identify smart-card-reader drivers, a behavior relevant to targeting cryptographic tokens used for banking authorization. Collected information is encoded and exfiltrated over an encrypted command-and-control channel. It can download additional modules, execute PowerShell commands, and has been reported to inject into legitimate processes.
Observed delivery methods include accounting-themed phishing and spearphishing messages bearing password-protected archives and malicious document-themed executables, as well as fraudulent software-download sites impersonating legitimate Russian cryptographic software. Its installation and operational behavior includes Windows Defender exclusion attempts, encoded PowerShell execution, registry-based payload storage, browser-history clearing, and deletion of volume shadow copies when running with administrative privileges.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
DarkWatchman is described as Hive0117's principal tool: a fileless modular JavaScript- and PowerShell-based trojan that resides in the Windows Registry and memory, with no executable payload files on disk. It uses Bitcoin OP_RETURN data as a dead-drop resolver for rotating C2 URLs.
DarkWatchman is described as Hive0117's principal tool: a fileless modular JavaScript- and PowerShell-based trojan that resides in the Windows Registry and memory, with no executable payload files on disk. It uses Bitcoin OP_RETURN data as a dead-drop resolver for rotating C2 URLs.
DarkWatchman is described as Hive0117's principal tool: a fileless modular JavaScript- and PowerShell-based trojan that resides in the Windows Registry and memory, with no executable payload files on disk. It uses Bitcoin OP_RETURN data as a dead-drop resolver for rotating C2 URLs.
DarkWatchman is described as Hive0117's principal tool: a fileless modular JavaScript- and PowerShell-based trojan that resides in the Windows Registry and memory, with no executable payload files on disk. It uses Bitcoin OP_RETURN data as a dead-drop resolver for rotating C2 URLs.
MITRE ATT&CK
Reporting
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Researchers reported multiple phishing campaigns delivering the DarkWatchman remote access trojan through Russian-themed lures, including a fake CryptoPro CSP site and messages imitating military conscription summons. Victims were directed to download password-protected or self-extracting archives that launched a downloader, dropped an obfuscated JavaScript backdoor, and decrypted a PowerShell-based keylogger. The malware collected keystrokes, clipboard contents, smart card data, and host information, then exfiltrated the data to command-and-control infrastructure. DarkWatchman stood out for storing configuration data, payload components, and stolen information in the Windows Registry rather than on disk, complicating detection and forensic recovery. The malware executed via wscript.exe, added Windows Defender exclusions, established persistence with Task Scheduler using generated task names, deleted installation artifacts, and in some cases removed volume shadow copies when running with elevated privileges. Reporting also linked the malware’s delivery and operation to heavy use of obfuscation and decryption techniques, including encrypted blobs and Base64-encoded PowerShell, consistent with MITRE ATT&CK T1140 behavior.
Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.