This cheeky new malware strain hides in the Windows Registry


Cybersecurity researchers from Pavilion have recently uncovered a new malware campaign in which Russian malicious actors allegedly target other Russians.
As reported by researchers Matt Stafford and Sherman Smith, in early November, the company spotted a lightweight, but highly potent JavaScript Remote Access Trojan (RAT), that was being deployed together with a C# keylogger which it has called “DarkWatchman”.
It is being distributed in a similar fashion to most malware today – through phishing emails. An email with a ZIP attachment would be sent out, containing what seems to be a text document. In reality, however, the file is a self-installing WinRAR archive that deploys both the RAT and the keylogger.
DarkWatchman is quite cheeky, the researchers further explained, as it does not store logged keys on the disk, but rather uses the Windows Registry fileless storage. The Trojan sets up a scheduled task, to run itself every time the victim logs into Windows.
Enabling ransomware attacks
After logging, it will execute a PowerShell script to compile the keylogger and launch it into memory.
“The keylogger is distributed as obfuscated C# source code that is processed and stored in the registry as a Base64-encoded PowerShell command. When the RAT is launched, it executes this PowerShell script which, in turn, compiles the keylogger (using CSC) and executes it,” the two researchers explained.
“The keylogger itself does not communicate with the C2 or write to disk. Instead, it writes its keylog to a registry key that it uses as a buffer. During its operation, the RAT scrapes and clears this buffer before transmitting the logged keystrokes to the C2 server.”
Speaking of the C2 server, DarkWatchman uses domain generation algorithms (DGA), generating up to 500 domains every day. That, the researchers explained, makes them highly resilient to domain seizure, and resistant to communication monitoring.
DarkWatchman has a very specific use case, Prevailion researchers believe. According to them, the RAT was designed by ransomware operators and distributed to third parties, who are then tasked with compromising target networks. Once the RAT is deployed, installing the actual malware becomes a lot easier.
Audio player loading… Cybersecurity researchers from Pavilion have recently uncovered a new malware campaign in which Russian malicious actors allegedly target other Russians. As reported by researchers Matt Stafford and Sherman Smith, in early November, the company spotted a lightweight, but highly potent JavaScript Remote Access Trojan (RAT), that was…
Recent Posts
- Salt Typhoon hackers used this clever technique to attack US networks
- Apple pulls encryption feature from UK over government spying demands
- Coinbase says the SEC has agreed to drop its crypto lawsuit
- Everything new on Max in March 2024
- Moroi preview: A grimdark action game that’s actually pretty funny
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010