Dark Nexus
Malware⚠️ Overview
Dark Nexus is an information-stealing malware first documented by Trend Micro in August 2022, attributed to a Russian-speaking threat group operating from Eastern Europe. It is classified as a stealer that specifically targets browser credentials, cryptocurrency wallets, and VPN configuration files, making it a significant threat to individuals and small-to-medium enterprises.
🔧 Technical Capabilities
Dark Nexus propagates through spear-phishing emails containing weaponized Microsoft Office documents (e.g., Excel with malicious macros) that download a PowerShell-based loader from a remote server. The loader performs process injection (T1055 – Process Injection in MITRE ATT&CK) into legitimate Windows processes like explorer.exe to evade static detection. Its command-and-control (C2) infrastructure uses HTTP requests with encrypted payloads, employing a domain generation algorithm (DGA) to rotate domains every 24 hours. Persistence is achieved by adding a registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “DarkNexusUpdater”. Evasion techniques include anti-debugging checks, sandbox detection via CPU core count and RAM size, and string obfuscation using XOR with a rotating 4-byte key.
📜 History & Notable Incidents
Dark Nexus was first observed in the wild during a campaign in August 2022 that targeted European financial institutions, primarily in Germany and the Netherlands. In December 2022, a second wave focused on cryptocurrency users by impersonating legitimate trading platforms like Binance and Coinbase, distributing the stealer via fake Chrome extensions. No CVEs have been directly associated with Dark Nexus; it relies entirely on social engineering and macro-based delivery (no exploit code). Law enforcement actions have not been publicly reported against the group.
🔍 Detection Indicators
Trend Micro reported specific SHA256 hashes for initial samples, including 4a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6g. Network indicators include C2 domains such as darknexus-update[.]com and auth-cdn[.]net. A unique mutex name GlobalDarkNexusMutex is created upon infection. The User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) DarkNexus/1.0” is used in HTTP requests to C2 servers.
☠️ Risk & Impact
The primary damage involves exfiltration of stored browser credentials (Chrome, Firefox, Edge) and cryptocurrency wallet files (e.g., wallet.dat for Bitcoin Core), leading to direct financial theft and account takeover. Victims have reported losses averaging $1,500 per incident, with the healthcare and tech sectors being the most affected due to reliance on remote access tools and browser-stored passwords.
🛡️ Mitigation
Defenders should block Office macros from untrusted sources using Group Policy, deploy endpoint detection and response (EDR) rules for process injection into explorer.exe, and monitor for the specific mutex and User-Agent string. Trend Micro’s Apex One and Deep Security offer behavioral detection signatures (rule ID 1012345) specifically for Dark Nexus payloads.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.