Skip to content

DarkWatchman

DarkWatchman is a Windows-based remote access trojan associated with the Hive0117 intrusion set and used in campaigns primarily targeting Russian organizations, including accountants, financial departments, and entities in aerospace and related sectors.

Profile source: Mallory opens in a new tab

DarkWatchman

Family profile

DarkWatchman is a Windows-based remote access trojan associated with the Hive0117 intrusion set and used in campaigns primarily targeting Russian organizations, including accountants, financial departments, and entities in aerospace and related sectors. First observed in 2021, it is notable for a registry-centric, low-footprint design that combines a JavaScript backdoor with a PowerShell keylogger and minimizes reliance on conventional dropped executables.

DarkWatchman commonly arrives through phishing or spearphishing lures, including password-protected archives and fake software download pages. Infection chains have used self-extracting archives that deploy an obfuscated JavaScript backdoor and an encrypted blob that decrypts into base64-encoded PowerShell implementing keylogging. The JavaScript component executes through Windows Script Host and has been observed compiling C# code on victim systems via csc.exe, reflecting compile-after-delivery tradecraft.

The malware establishes persistence through scheduled tasks and stores configuration data, staged payloads, and collected information in the Windows Registry. It queries the Registry to determine whether it is already installed and modifies Registry values to retain configuration strings, encoded keylogger content, and collected output. This registry-heavy approach reduces on-disk artifacts and supports defense evasion. DarkWatchman has also been observed deleting installation artifacts, clearing browser history, uninstalling malicious components from the Registry, and deleting volume shadow copies when privileges permit.

Its capabilities include remote command execution, including PowerShell execution, host profiling, and collection of victim metadata such as username and OS locale. It can enumerate antivirus products and gather peripheral-related information, including signed Plug and Play drivers for smart card readers. The PowerShell keylogger captures keystrokes and has also been reported collecting clipboard and smart-card-related information relevant to abuse of remote banking workflows. Collected data is staged in the Registry, encoded before transmission, and exfiltrated over an encrypted command-and-control channel using TLS.

Operationally, DarkWatchman has been linked both to espionage-style targeting and financially motivated intrusions. In campaigns against accountants and business users, operators used the malware to gain access to remote banking environments and facilitate theft. The malware’s combination of JavaScript execution, PowerShell-based collection, registry-backed storage, and scheduled-task persistence makes it a distinctive fileless-style RAT focused on stealthy post-compromise control and data theft on Windows systems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 2, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • FR1

Leading providers

  • AS56971 Cloud1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

1 named in public reporting
Hive0117

We attribute the executable with a high level of confidence to the DarkWatchman malware family, a custom-made backdoor leveraged the intrusion set Hive0117.

MITRE ATT&CK

DarkWatchman in ATT&CK

62 distinct techniques

Techniques

62 techniques
T1059.001 PowerShell T1027.004 Compile After Delivery T1033 System Owner/User Discovery T1082 System Information Discovery T1518.001 Security Software Discovery T1112 Modify Registry T1027 Obfuscated Files or Information T1059.007 JavaScript T1070.004 File Deletion T1560 Archive Collected Data T1056.001 Keylogging T1053.005 Scheduled Task T1204 User Execution T1053 Scheduled Task/Job T1012 Query Registry T1059 Command and Scripting Interpreter T1564 Hide Artifacts T1087 Account Discovery T1566 Phishing T1071 Application Layer Protocol T1218 System Binary Proxy Execution T1140 Deobfuscate/Decode Files or Information T1608.001 Upload Malware T1036 Masquerading T1041 Exfiltration Over C2 Channel T1566.001 Spearphishing Attachment T1204.002 Malicious File T1565 Data Manipulation T1120 Peripheral Device Discovery T1560.001 Archive via Utility T1115 Clipboard Data T1083 File and Directory Discovery T1071.001 Web Protocols T1132 Data Encoding T1074 Data Staged T1059.003 Windows Command Shell T1573 Encrypted Channel T1047 Windows Management Instrumentation T1592 Gather Victim Host Information T1497.001 System Checks T1070 Indicator Removal T1070.009 Clear Persistence T1217 Browser Information Discovery T1070.003 Clear Command History T1490 Inhibit System Recovery T1219 Remote Access Tools T1078 Valid Accounts T1105 Ingress Tool Transfer T1027.013 Encrypted/Encoded File T1614 System Location Discovery T1129 Shared Modules T1027.011 Fileless Storage T1010 Application Window Discovery T1124 System Time Discovery T1568.002 Domain Generation Algorithms T1573.002 Asymmetric Cryptography T1574 Hijack Execution Flow T1074.001 Local Data Staging T1005 Data from Local System T1027.015 Compression T1132.001 Standard Encoding T1027.010 Command Obfuscation

Reporting

Research mentioning DarkWatchman

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

May 13
Splunk Research

Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content

Sep 7
Security Intelligence

New Hive0117 phishing campaign imitates conscription summons to deliver DarkWatchman malware | IBM

Researchers reported multiple phishing campaigns delivering the DarkWatchman remote access trojan through Russian-themed lures, including a fake CryptoPro CSP site and messages imitating military conscription summons. Victims were directed to download password-protected or self-extracting archives that launched a downloader, dropped an obfuscated JavaScript backdoor, and decrypted a PowerShell-based keylogger. The malware collected keystrokes, clipboard contents, smart card data, and host information, then exfiltrated the data to command-and-control infrastructure. DarkWatchman stood out for storing configuration data, payload components, and stolen information in the Windows Registry rather than on disk, complicating detection and forensic recovery. The malware executed via wscript.exe, added Windows Defender exclusions, established persistence with Task Scheduler using generated task names, deleted installation artifacts, and in some cases removed volume shadow copies when running with elevated privileges. Reporting also linked the malware’s delivery and operation to heavy use of obfuscation and decryption techniques, including encrypted blobs and Base64-encoded PowerShell, consistent with MITRE ATT&CK T1140 behavior.

May 25
Cyble Blog Historic

Invicta Stealer Spreads Via Fake GoDaddy Refund Invoices

Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.

May 5
Cyble

DarkWatchMan RAT Spreads Via Phishing Sites

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.