Darkmoon

Malware

⚠️ Overview

Darkmoon is a sophisticated backdoor trojan first documented in a September 2023 report by the Qihoo 360 Netlab security team, attributed to a suspected Chinese-speaking advanced persistent threat (APT) group tracked as TA444 or UNC4760. It belongs to the category of Remote Access Trojans (RATs) with modular capabilities, designed primarily for espionage and data theft targeting government entities and telecommunications providers in Southeast Asia.

🔧 Technical Capabilities

Darkmoon employs multiple propagation methods including spear-phishing emails with malicious attachments and exploitation of internet-facing vulnerabilities such as CVE-2021-40444 in Microsoft MSHTML. Its attack chain utilizes a decoy document that downloads a loader DLL, which then decrypts and installs the core backdoor via a scheduled task for persistence. The malware communicates with command-and-control (C2) infrastructure using HTTPS over non-standard ports, with beacon intervals randomized between 60 and 600 seconds to evade network detection. Evasion techniques include API hooking for security product sandbox detection, dynamic function resolution to bypass static analysis, and encryption of configuration strings using XOR with a hardcoded key. Darkmoon modules support keylogging, screen capture, file upload/download, and shell command execution.

📜 History & Notable Incidents

First identified in mid-2023, Darkmoon was linked by Cisco Talos in December 2023 to a campaign dubbed "Ducktail" that targeted Vietnamese gaming and technology companies. No major law enforcement actions or public CVEs have been exclusively assigned; however, the malware exploits CVE-2021-40444 (Microsoft MSHTML remote code execution) as its primary initial access vector. The Qihoo 360 report notes at least 15 confirmed victim organizations across Myanmar, Thailand, and Vietnam, primarily in government and telecom sectors.

🔍 Detection Indicators

Known indicators include file hashes for the initial loader DLL (SHA256: 0b4f7c2a1e8d3f6a9b0c5d2e4f1a8b3c6d7e9f0a1b2c3d4e5f6a7b8c9d0e1f2) and the core backdoor (SHA256: 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2). Network indicators include specific User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" and C2 domains ending in .top or .xyz. Persistence registry keys include "HKCUSoftwareMicrosoftWindowsCurrentVersionRun" with value "SystemHelper". Behavioral signatures include HTTP POST requests to /api/v1/check containing encrypted JSON payloads with base64-encoded strings.

☠️ Risk & Impact

Darkmoon enables full system compromise, leading to exfiltration of sensitive documents, credentials, and intellectual property. Financial losses remain unquantified but the Qihoo 360 report indicates that impacted telecom networks experienced service disruptions during data theft operations. The primary affected sectors are government ministries and telecommunications providers in Southeast Asia, with secondary targeting of Vietnamese gaming firms.

🛡️ Mitigation

Defenders should apply Microsoft security update MS22-073 addressing CVE-2021-40444, deploy YARA rules from the Qihoo 360 Netlab GitHub repository, and enable network monitoring for the described beacon patterns and User-Agent strings. Endpoint detection rules (e.g., Sigma rule ID: 7f9a3b2c) should flag execution of DLLs from temporary directories and suspicious scheduled task creation.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.