DarkVNC is a Windows hidden virtual network computing (hVNC) remote-access trojan that creates a concealed virtual desktop on an infected system, enabling an operator to view and control that desktop through VNC technology without exposing the activity on the victim’s visible desktop. It has been used to remotely control compromised computers and transfer stolen victim data to command-and-control infrastructure. DarkVNC has been distributed by IcedID and has also been observed as a payload wrapped by the TrickGate packing service. A 2016–2017 campaign alleged by U.S. prosecutors used fraudulent accounts on a freelance-employment platform to send malicious Excel attachments; victims who enabled embedded macros downloaded DarkVNC or TVRAT. The campaign allegedly targeted freelance-platform users at scale and used compromised-system access and stolen data to support fraud. DarkVNC should not be conflated with LOBSHOT or Anubis VNC merely because of hVNC functionality, VNC traffic, or possible shared code.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign included the use of a variant of AZORult, an information-stealing malware; as well as the RAT Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
Today's diary reviews an example of Monster Libra pushing IcedID on Thursday 2022-08-11, and that IcedID infection led to Dark VNC activity and Cobalt Strike.
We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening an attachment prompted the recipient to enable or execute an embedded macro. If the user complied, the macro downloaded malware from the internet.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access malware alleged to have provided hidden control of victims' computers and supported theft and transfer of victim data to command-and-control infrastructure.
A remote-access malware tool used to control infected computers remotely and exfiltrate stolen data to command-and-control servers.
Remote-access malware that creates a hidden virtual desktop on the victim system for attacker control over VNC. It steals information and sends collected data to a command-and-control server.
A remote-access trojan allegedly distributed via malicious Excel macro attachments. It provides remote control through VNC Viewer functionality and sends stolen data from victim systems to a command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.