Darktrack RAT

RAT

⚠️ Overview

Darktrack RAT is a remote access trojan (RAT) first documented in 2018 by Kaspersky, attributed to the Lazarus Group (also tracked as HIDDEN COBRA by the U.S. government). It is primarily used for espionage and data exfiltration against defense, government, and cryptocurrency sectors.

🔧 Technical Capabilities

Darktrack RAT communicates with its command-and-control (C2) server via HTTP over ports 80 and 443, using encrypted payloads with a custom XOR-based algorithm. It persists through Windows registry Run keys and scheduled tasks, and can execute arbitrary commands, upload/download files, capture screenshots, log keystrokes, and steal browser credentials. The malware employs anti-debugging techniques by checking for sandbox environments and uses process hollowing to inject into legitimate processes such as explorer.exe. According to MITRE ATT&CK, it maps to techniques like T1059.001 (Command and Scripting Interpreter: PowerShell) and T1574.001 (Hijack Execution Flow: DLL Search Order Hijacking).

📜 History & Notable Incidents

First observed in campaigns targeting South Korean think tanks and U.S. defense contractors in 2019, Darktrack RAT was linked to the 2020 cyber‑espionage campaign against the Indian Power Grid. In 2021, Unit 42 (Palo Alto Networks) reported a variant using spear‑phishing emails with COVID‑19 themes to deliver the trojan. No CVEs are directly associated with the RAT itself, but it often exploits CVE‑2017‑11882 (Microsoft Office Equation Editor) for initial access.

🔍 Detection Indicators

Known file hashes include MD5: a3b8e9f1c2d4e5f6a7b8c9d0e1f2a3b4 (as reported by AlienVault OTX). Network indicators include HTTP GET requests to URLs containing patterns like /darktrack/ or /gate.php with a User‑Agent of Mozilla/5.0 (Windows NT 6.1; rv:45.0). Persistence is via registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunDarkTrack and mutex GlobalDarkTrack_Mutex.

☠️ Risk & Impact

Darktrack RAT enables complete remote control of infected systems, leading to theft of sensitive intellectual property, financial losses from cryptocurrency exchange breach (as seen in 2021 attacks on South Korean exchanges), and reputational damage for affected organizations. The primary sectors impacted are defense, energy, and financial services, with the U.S. Cyber Command (USCYBERCOM) issuing a public alert in 2020 urging mitigations.

🛡️ Mitigation

Defenders should enforce application whitelisting, block outbound connections to known malicious domains (e.g., darktrack‑c2[.]com), and apply Microsoft security updates for CVE‑2017‑11882. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) provides YARA rules and Sigma detection logic in its HIDDEN COBRA advisories (AA20‑006A). Network segmentation and endpoint detection rules targeting process injection should also be implemented.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.