Malware.View on attack.mitre.org
DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
DarkWatchman can collect files from a compromised host. |
| T1010 Application Window Discovery |
DarkWatchman reports window names along with keylogger information to provide application context. |
| T1012 Query Registry |
DarkWatchman can query the Registry to determine if it has already been installed on the system. |
| T1027.004 Compile After Delivery |
DarkWatchman has used the |
| T1027.010 Command Obfuscation |
DarkWatchman has used Base64 to encode PowerShell commands. |
| T1027.011 Fileless Storage |
DarkWatchman can store configuration strings, keylogger, and output of components in the Registry. |
| T1027.015 Compression |
DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims. |
| T1033 System Owner/User Discovery |
DarkWatchman has collected the username from a victim machine. |
| T1036 Masquerading |
DarkWatchman has used an icon mimicking a text file to mask a malicious executable. |
| T1047 Windows Management Instrumentation |
DarkWatchman can use WMI to execute commands. |
| T1053.005 Scheduled Task |
DarkWatchman has created a scheduled task for persistence. |
| T1056.001 Keylogging |
DarkWatchman can track key presses with a keylogger module. |
| T1059.001 PowerShell |
DarkWatchman can execute PowerShell commands and has used PowerShell to execute a keylogger. |
| T1059.003 Windows Command Shell |
DarkWatchman can use `cmd.exe` to execute commands. |
| T1059.007 JavaScript |
DarkWatchman uses JavaScript to perform its core functionalities. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.