SYMBOLCOMMON_NAMEaka. SYNONYMS
win.darkvision_rat (Back to overview)

DarkVision RAT

VTCollection    

DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020. Written in C/C++ and assembler, it has gained popularity due to its low cost and broad range of functionalities, including keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. In July 2024, a malware campaign was observed distributing DarkVision_RAT using PureCrypter as a loader. This RAT communicates with its command and control server through a custom network protocol via sockets. It also employs evasion and privilege escalation techniques such as DLL hijacking, self-elevation, and process injection. DarkVision_RAT supports a wide array of commands and plugins, enabling additional capabilities like keylogging, remote access, password theft, audio recording, and screenshot capture.

References
2024-10-10 ⋅ Zscaler ⋅ Muhammed Irfan V A
Technical Analysis of DarkVision RAT
DarkVision RAT
Yara Rules
[TLP:WHITE] win_darkvision_rat_auto (20260917 | Detects win.darkvision_rat.)
rule win_darkvision_rat_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.darkvision_rat."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkvision_rat"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488bd1 488d4c2428 e8???????? 4863442468 48634c2420 488d4c0c28 }
            // n = 6, score = 100
            //   488bd1               | mov                 dword ptr [esp + 0x64], 0
            //   488d4c2428           | xor                 edx, edx
            //   e8????????           |                     
            //   4863442468           | dec                 eax
            //   48634c2420           | mov                 ecx, dword ptr [esp + 0x30]
            //   488d4c0c28           | dec                 eax

        $sequence_1 = { 8b842480010000 0faf8424a8000000 89842480010000 8b842480010000 488b4c2460 }
            // n = 5, score = 100
            //   8b842480010000       | dec                 eax
            //   0faf8424a8000000     | mov                 ecx, dword ptr [esp + 0x210]
            //   89842480010000       | dec                 eax
            //   8b842480010000       | mov                 dword ptr [eax], ecx
            //   488b4c2460           | dec                 eax

        $sequence_2 = { 89442430 8b442430 8b4c2420 03c8 8bc1 c1e012 }
            // n = 6, score = 100
            //   89442430             | cmp                 dword ptr [ecx + eax + 8], 0
            //   8b442430             | je                  0x8d
            //   8b4c2420             | mov                 eax, 1
            //   03c8                 | dec                 eax
            //   8bc1                 | arpl                word ptr [esp], ax
            //   c1e012               | dec                 eax

        $sequence_3 = { 7408 8bcb ff15???????? e8???????? 488d1552650000 488d0d23650000 e8???????? }
            // n = 7, score = 100
            //   7408                 | add                 ecx, eax
            //   8bcb                 | dec                 eax
            //   ff15????????         |                     
            //   e8????????           |                     
            //   488d1552650000       | mov                 eax, ecx
            //   488d0d23650000       | mov                 dword ptr [esp + 0xa0], eax
            //   e8????????           |                     

        $sequence_4 = { c1e00d 8b4c2420 8b542410 03d1 }
            // n = 4, score = 100
            //   c1e00d               | dec                 eax
            //   8b4c2420             | mov                 dword ptr [esp + 0x38], eax
            //   8b542410             | dec                 eax
            //   03d1                 | lea                 eax, [esp + 0x100a0]

        $sequence_5 = { 48894c2408 4881ecb8020000 c744245000000000 488d542444 488b8c24c0020000 e8???????? 4889442448 }
            // n = 7, score = 100
            //   48894c2408           | dec                 eax
            //   4881ecb8020000       | mov                 ecx, dword ptr [esp + 0x148]
            //   c744245000000000     | test                eax, eax
            //   488d542444           | dec                 esp
            //   488b8c24c0020000     | lea                 ecx, [esp + 0x364]
            //   e8????????           |                     
            //   4889442448           | inc                 esp

        $sequence_6 = { 4889442460 c784249801000000000000 eb10 8b842498010000 ffc0 89842498010000 0fb7442476 }
            // n = 7, score = 100
            //   4889442460           | mov                 eax, 3
            //   c784249801000000000000     | xor    edx, edx
            //   eb10                 | dec                 eax
            //   8b842498010000       | mov                 ecx, dword ptr [esp + 0x440]
            //   ffc0                 | dec                 eax
            //   89842498010000       | mov                 dword ptr [esp + 0x30], 0
            //   0fb7442476           | dec                 esp

        $sequence_7 = { 488d8c2470010000 ff15???????? 48898424c0010000 4883bc24c001000000 0f848a000000 488b8424c0010000 488b4018 }
            // n = 7, score = 100
            //   488d8c2470010000     | shr                 ecx, 0x19
            //   ff15????????         |                     
            //   48898424c0010000     | or                  eax, ecx
            //   4883bc24c001000000     | mov    ecx, dword ptr [esp + 0x38]
            //   0f848a000000         | xor                 ecx, eax
            //   488b8424c0010000     | mov                 eax, ecx
            //   488b4018             | mov                 dword ptr [esp + 0x38], eax

        $sequence_8 = { 33c0 e9???????? 4863842400020000 488b44c460 4889842408020000 488b842408020000 }
            // n = 6, score = 100
            //   33c0                 | mov                 dword ptr [esp + 0x338], eax
            //   e9????????           |                     
            //   4863842400020000     | dec                 eax
            //   488b44c460           | lea                 ecx, [esp + 0x328]
            //   4889842408020000     | test                eax, eax
            //   488b842408020000     | je                  0x1280

        $sequence_9 = { 488d0507150200 4a8b0ce0 41f6440f0880 0f84fe020000 33db 4d8be5 }
            // n = 6, score = 100
            //   488d0507150200       | mov                 ecx, dword ptr [esp + 0x100]
            //   4a8b0ce0             | call                dword ptr [esp + 0x210]
            //   41f6440f0880         | dec                 eax
            //   0f84fe020000         | cmp                 dword ptr [esp + 0x278], 0
            //   33db                 | je                  0x8e5
            //   4d8be5               | dec                 eax

    condition:
        7 of them and filesize < 618496
}
Download all Yara Rules