Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DarkVision

71
Global rank
58 infographic chevron month
Month rank
95 infographic chevron week
Week rank

DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.

RAT
Type
Unknown
Origin
1 May, 2020
First seen
4 October, 2026
Last seen

How to analyze DarkVision with ANY.RUN

RAT
Type
Unknown
Origin
1 May, 2020
First seen
4 October, 2026
Last seen

IOCs

IP addresses
82.29.67.160
154.23.184.57
154.91.34.165
107.174.192.179
118.194.235.187
142.251.127.94
2.23.245.19
104.26.9.202
139.99.85.213
188.114.97.3
132.226.8.169
176.65.144.23
149.154.167.99
142.251.110.154
150.171.28.11
45.141.233.69
142.251.13.138
142.251.110.132
172.67.74.9
2.20.142.2
Hashes
74441313bb1fb62500484443c4937e90d4e335351a4fcd12a9ac48448500e33e
a17fcf0a2f50e2d495e4f90ce263410edc183add6c62699a2facbccf60410f74
4094d158e3b0581ba433a46d0dce62f99d8c0fd1b50bb4d0517ddc0a4a1fde24
99653a38c445ae1d4c373ee672339fd47fd098e0d0ada5f0be70e3b2bf711d38
c158322bd963d2a68ffc878d72213a7394d8c16de72279771ffc924365eec0df
59345c006cd9bde5ef532aae1f119758d45030993181c272bb0dd6fc0c5d01e5
2ae1142b08d296c25000e451237ea919f981da28f6a723d39540f43f18bac762
5639c845d56dedecd2cfdb082b734593b5d618a87f1bd8ec612a8b3f4245566a
32ae9531405ef3c59448fe6dbd3be435e726eb17f3ca0d16530a4c6317dea286
7c68f28c6995f47dd77596bab28c6b4388ff93840c3becfd37733ddb640cd0cd
40cf1af5650b699a947899d2b43a00dcb64cdeaf080651c82a7930910c1c03f4
ec249b0dab6fda20cc24f0f25a504c55a05b23fb6cbb4938aa7a41df0c8744b6
0162159b64eb092f94964faf937f263fb9947b25d40e0d82bd3224d136a140de
77eed9211cd8464482f0da3fac4c0f003c2b8a6d76f15445927e66400f102d60
6558013f984e594bb57534910ce0b17bfa15da3cc9bb4b6e0b5c6e4ddf9eb14e
a7109b8374dffa7a0cd69558990f7e96fea9ef61736d89043dad5a6694cdfa4a
558bbe6193a202dcb00cc441421f5d838764e495b8e4d2e10877db7f661b8cd5
db3ac1fd3d65df45d805adb8dfe0c5209db07ef93406db17dfb783dd8048720a
19acfa0adce363a9c9a3be73f5ec0fac0dcf3c630ce18125fd265040ad6ffb6c
1e4d06cfa669c24bba17e9c45ea56eab8549ad2aed09880fe0d93926086bb673
Domains
watson.events.data.microsoft.com
dontlookhere.com
pagead2.googlesyndication.com
17.aa.4t.com
gcc-prtnrs.top
google.com
plausible.io
update.googleapis.com
fonts.googleapis.com
fundingchoicesmessages.google.com
www.bing.com
ep2.adtrafficquality.google
ep1.adtrafficquality.google
config.edge.skype.com
self.events.data.microsoft.com
lh3.googleusercontent.com
fonts.gstatic.com
crl.microsoft.com
reallyfreegeoip.org
dbensoaupthreesdopsopsseead.ydns.eu
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:j2zgf_dfcsovbjb1sddex2-qiarlocwyqghnx0b53pk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://login.live.com/ppsecure/deviceaddcredential.srf
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://uploadnow.io/f/0bcds7g
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://uploadnow.io/en/share?utm_source=0bcds7g
https://cdn.uploadnow.io/_next/static/css/cda03e3a1ab65c17.css
https://cdn.uploadnow.io/_next/static/css/df97d9751ec3abda.css
https://cdn.uploadnow.io/_next/static/css/ae110469aab9e883.css
https://cdn.uploadnow.io/_next/static/css/5ded0d5ca9ecc5c1.css
https://cdn.uploadnow.io/_next/static/chunks/webpack-541c27ed8494cc3b.js
https://cdn.uploadnow.io/_next/static/chunks/framework-b6335179e7eea00c.js
https://cdn.uploadnow.io/_next/static/chunks/main-86f0684c1b20f38d.js
https://cdn.uploadnow.io/_next/static/chunks/pages/_app-a7a0c0b843b84887.js
https://cdn.uploadnow.io/_next/static/chunks/62867-950590631f5ceb03.js
Last Seen at
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

What is DarkVision RAT Malware?

DarkVision RAT is a highly customizable Remote Access Trojan that emerged in 2020, gaining notoriety for its affordability and extensive feature set. Priced as low as $60 on platforms like Hack Forums, it has become a popular tool among cybercriminals, including those with minimal technical skills. Written in C/C++ and assembly, DarkVision RAT poses a significant threat to individuals and organizations worldwide due to its stealthy capabilities and sophisticated attack chain.

Its modular design makes it easy to adapt for credential theft, surveillance, lateral maneuvers, and persistence. Recent technical analyses show it is often delivered via multi-stage loaders (Donut shellcode / PureCrypter and implements a bespoke network protocol to communicate with command-and-control (C2) servers. The RAT also uses a variety of evasion and privilege-escalation techniques (DLL hijacking, process injection, autorun/backdoor patterns).

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

DarkVision RAT Victimology

The malware targets primarily Windows endpoints: home users, SMEs and enterprise workstations.

Its distribution profile — opportunistic criminal operators (ransomware / data theft actors, commodity cybercriminals) and less skilled attackers who buy prebuilt RAT kits.

Sectors observed in campaigns: general business environments where user workstations have internet access and credentials that can unlock broader access (finance, professional services, manufacturing have all been impacted in commodity RAT campaigns). The availability and low price point of DarkVision make it attractive to a wide array of attackers.

DarkVision RAT Typical Attack Chain

ANY.RUN’s Interactive Sandbox provides fresh samples of DarkVision recently detonated and thoroughly studied by our half-a-million community of threat analysts.

Let’s explore a sample to see the main stages of an attack chain on a live example.

View analysis

DarkVision analysis in Interactive Sandbox DarkVision sample analysis in the Interactive Sandbox

  1. Initial Infection and Process Masquerading The DarkVision Remote Access Trojan (RAT) begins its operation by copying itself to the directory: C:\ProgramData\windows\windows.exe.

DarkVision in Windows system folder DarkVision establishes itself in a system directory

This location and filename are deliberately chosen to mimic a legitimate Windows executable, making it harder for the user or antivirus software to recognize it as malicious.

  1. Registry Modifications Once executed, the malware creates a new registry key under: HKEY_CURRENT_USER\SOFTWARE\

It then adds three entries, each identified by a hardcoded GUID (Globally Unique Identifier). These values store Current System Time in a FILETIME structure.

Registry changes by DarkVision DarkVision registry activity

RAT File Content – a large block of hexadecimal data representing the malicious binary’s content.

DarkVision data file Binary file viewable in ANY.RUN Sandbox

RAT File Path – the full filesystem path to the RAT executable.

DarkVision registry modification for establishing in the system Another DarkVision registry modification for establishing in the system

These registry entries allow the malware to preserve important execution details and can be used for reloading the payload or tracking the system’s infection state.

  1. Persistence Mechanism

To ensure it runs automatically after the system restarts, DarkVision RAT drops a batch script (.bat) file.

Script content example:

Bat file static analysis in ANY.RUN Sandbox Bat file static analysis in ANY.RUN Sandbox

The script is then linked via a .lnk shortcut placed in the user’s startup folder

DarkVision persistence mechanism DarkVision persistence mechanism

This guarantees execution every time the system boots.

  1. Process Injection

The malware injects its code into multiple legitimate Windows processes to avoid detection and run with elevated privileges. In this observed case, the target processes included explorer.exe, svchost.exe, сmd.exe

DarkVision injecting system Windows processes DarkVision injecting system Windows processes

  1. Command and Control (C2) Communication After setup, DarkVision RAT connects to its hardcoded Command and Control server:

DarkVision network activity Network activity signaling malicious activity

This connection is used to receive the C2 IP server and port, as well as later instructions from the threat actor, and to send back collected information about the infected machine. The screenshots confirm DNS queries to the *.ddns.net domain, flagged by Suricata IDS as potentially malicious traffic.

Once communication is established, the RAT stays idle, waiting for the attacker’s commands. Potential capabilities include file exfiltration, system manipulation, additional payload downloads, and real-time surveillance.

How DarkVision RAT Generally Functions

DarkVision RAT typically spreads through a multi-stage infection chain, often initiated via phishing campaigns or malicious downloads:

  • Initial Stage: A .NET executable, protected by .NET Reactor, executes a command cmd /c timeout 10 and decrypts second-stage shellcode using Triple DES (3DES) with Base64-encoded keys and IVs.
  • Second Stage: The Donut loader, an x86 position-independent shellcode, decrypts and loads a .NET assembly using the Chaskey block cipher.
  • Third Stage: PureCrypter, a .NET assembly, decompresses and deserializes a protobuf structure containing the encrypted DarkVision RAT payload (AES-CBC). It also executes PowerShell commands to add Windows Defender exclusions for malicious file paths and processes.
  • Fourth Stage: The RAT copies itself to a designated path (e.g., %APPDATA%\photos\System.exe), establishes persistence, and initiates C2 communication. Phishing emails with malicious attachments or links to domains like nasyiahgamping[.]com/yknoahdrv.exe are common delivery vectors.

DarkVision RAT operates through a multi-stage attack chain, leveraging sophisticated techniques to infiltrate and persist on systems:

  • Dynamic API Resolution: Uses GetProcAddress and LoadLibrary to resolve APIs dynamically, avoiding antivirus hooks. API names are XOR-encoded with the key [19 72 19 72].
    • Command-Line Parsing: Utilizes Globally Unique Identifiers (GUIDs) as command-line arguments for registry keys, folder names, and file names, ensuring randomness to evade detection.
  • Privilege Escalation: Employs DLL hijacking targeting WinSAT.exe and DXGI.DLL for auto-elevation on Windows 10 and above.
    • Persistence Mechanisms: Achieves persistence via:
  • Startup Folder: Creates a batch script and shortcut in the Windows startup folder.
  • Autorun Keys: Adds entries to HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run or HKLM for system-wide persistence.
  • Task Scheduler: Uses the ITaskService COM interface to schedule malicious tasks.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

What DarkVision RAT Can Do to an Endpoint Device

DarkVision RAT is equipped with an extensive array of malicious capabilities that can severely compromise endpoint devices:

  • Keylogging: Captures keystrokes to steal sensitive information like usernames, passwords, and other credentials.
  • Screen Capture: Takes screenshots or records the victim’s desktop to monitor activities.
  • File Manipulation: Allows attackers to upload, download, delete, or modify files on the infected system.
  • Process Injection: Injects malicious code into legitimate processes to evade detection.
  • Remote Code Execution: Executes arbitrary commands on the victim’s device, enabling full control.
  • Password Theft: Extracts credentials from browsers, applications, and system files.
  • **Audio and Webcam Capture: Records audio or video, compromising user privacy.
  • Remote Access: Provides attackers with direct control over the infected device via Virtual Network Computing (VNC) or reverse proxy operations. These capabilities are often implemented through encrypted plugins, which remain in plain text only in memory, enhancing the malware’s stealth.

How DarkVision RAT Threatens Businesses and Organizations

  • Data theft: sensitive files and credentials exfiltrated lead to IP loss, compliance breaches, and downstream fraud.
  • Lateral movement: stolen credentials and remote shells enable access to privileged systems.
  • Surveillance & espionage: persistent access permits long-term monitoring of sensitive activity.
  • Operational disruption: attackers can deploy ransomware or destructive commands from an already present RAT.
  • Reputation & legal exposure: stolen customer or employee data leads to regulatory and PR fallout. Because it’s inexpensive and modular, attackers can quickly reuse or reconfigure it for targeted campaigns.

Gathering Threat Intelligence on DarkVision RAT Malware

Threat intelligence (TI) gives security teams:

  • Up-to-date IOCs (domains, IPs, hashes) to block and hunt.
  • Campaign context (delivery method, loader chains) to prioritize detection coverage (e.g., inspect for Donut/PureCrypter stages).
  • Behavioral TTPs mapped to frameworks (MITRE ATT&CK) so defenders can create analytic detections and response playbooks.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deep into contextual data on DarkVision. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"darkvision"

DarkVision samples found via Threat Intelligence Lookup DarkVision sample analyses found via Threat Intelligence Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DarkVision RAT remains a formidable threat due to its affordability, versatility, and sophisticated evasion techniques. Its ability to compromise endpoint devices, steal sensitive data, and maintain persistence poses significant risks to businesses and individuals alike. By understanding its attack chain, implementing robust detection and prevention measures, and leveraging threat intelligence, organizations can mitigate the risks posed by this malware.

Proactive cybersecurity practices, including user education, endpoint protection, and real-time monitoring, are essential to defend against DarkVision RAT and similar threats in the evolving cyber landscape.

Gather fresh actionable threat intelligence for quick detection and response via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More
SVCStealer screenshot
SVCStealer
svcstealer
SVCStealer is an information-stealing malware targeting sensitive user data through spear-phishing email attachments. It systematically extracts credentials, financial data, and system information from various applications, including browsers and messaging platforms.
Read More
Tykit screenshot
Tykit
tykit
Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.
Read More
Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More