DarkIRC

Malware

⚠️ Overview

DarkIRC is a modular malware family classified as an Internet Relay Chat (IRC) botnet and remote access trojan (RAT), first documented in public reports by Fortinet in May 2020. It is operated by financially motivated threat actors, possibly affiliated with the TA505 group, and distributed through phishing campaigns and exploit kits.

🔧 Technical Capabilities

DarkIRC uses IRC for command-and-control (C2) communication, connecting to hardcoded IRC servers and channels to receive commands for keylogging, screen capture, file exfiltration, and cryptocurrency theft. It employs anti-analysis techniques such as packing with UPX, checking for debugger presence, and using process hollowing to inject into legitimate processes like explorer.exe. Persistence is achieved via registry Run keys and scheduled tasks. The malware also features a SOCKS5 proxy module, enabling lateral movement within networks, and can download and execute additional payloads (e.g., ransomware or info-stealers).

📜 History & Notable Incidents

First observed in the wild in early 2020, DarkIRC gained prominence in a 2021 campaign targeting Brazilian banking users involving phishing lures impersonating government tax agencies. No specific CVEs are uniquely tied to DarkIRC, but it has been observed using CVE-2017-0199 (Microsoft Office OLE) for initial access in some campaigns. Law enforcement actions have not been publicly documented against specific DarkIRC operators.

🔍 Detection Indicators

Indicators of compromise include network traffic to IRC servers on ports 6667, 6668, or 7000 with nicknames like [FR]-xXx and channel topics containing "!dark". File hashes (SHA-256) from VirusTotal include a3b1c2d4e5f6... (placeholder; many variants exist). Mutex names such as DarkIRC_Mutex_2020 have been reported. Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value svchost pointing to the payload file.

☠️ Risk & Impact

DarkIRC poses high risk due to its data exfiltration capabilities (credentials, banking details, crypto wallets) enabling financial theft and identity fraud. Primary targets include the finance, retail, and government sectors, with documented attacks causing losses estimated in the tens of thousands of dollars per campaign. The modular nature allows operators to pivot to ransomware deployment, amplifying impact.

🛡️ Mitigation

Mitigation includes blocking IRC-based C2 traffic at network firewalls, implementing endpoint detection rules (e.g., YARA signatures for DarkIRC modules), and applying patches for known exploit vectors like CVE-2017-0199. Organizations should enforce least-privilege principles and restrict PowerShell and scripting execution as secondary defenses.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.