DarkWatchman is a fileless JavaScript-based malware family used in phishing-driven intrusions and associated in the provided content with the Hive0117 threat group. It has been delivered via spearphishing emails containing malicious ZIP archives, and separate reporting in the content describes campaigns using password-protected RAR archives themed as accounting documents. In those campaigns, attackers targeted company accountants and financial departments to gain access to corporate remote banking systems and steal funds. Executing the lure file installs DarkWatchman and downloads a keylogger module. Reported victims include organizations in Russia, Belarus, Kazakhstan, and Uzbekistan, and one cited bulletin notes Hive0117 used DarkWatchman in a phishing campaign targeting Eastern European countries.
Capabilities directly described in the content include storing configuration strings, keylogger data, component output, and staged local data in the Windows Registry; querying the Registry to determine whether it is already installed; searching the system for antivirus products; identifying the OS locale; collecting the username from the victim machine; listing signed Plug and Play drivers for smart card readers; retrieving browser history; executing commands via WMI; executing PowerShell commands, including using PowerShell to run a keylogger; encoding data in hexadecimal before sending it to command-and-control infrastructure; and using TLS to encrypt its C2 channel. The malware can also delete shadow volumes using vssadmin.exe.
The content also describes cleanup and anti-forensics behavior: DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear browser history. In the financially motivated campaigns described, the downloaded keylogger intercepted keystrokes, monitored clipboard contents, and tracked connection of cryptographic tokens commonly used for remote banking access. When such a token was connected, operators reportedly moved to a next stage and deployed remote access tooling including LiteManager, BitRAT, and malware with hVNC functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Злоумышленники нацелились на бухгалтеров компаний и заражают их машины малварью DarkWatchman, чтобы затем использовать доступ к системам дистанционного банковского обслуживания (ДБО) для хищения денег. ... После запуска такого файла в систему жертвы устанавливается вредонос DarkWatchman, который загружает на зараженную машину модуль кейлоггера.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
DarkWatchman gives attackers the ability to run commands remotely...
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.
После запуска такого файла в систему жертвы устанавливается вредонос DarkWatchman, который загружает на зараженную машину модуль кейлоггера. Тот, в свою очередь, перехватывает нажатия клавиш...
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Тот, в свою очередь, перехватывает нажатия клавиш, следит за содержимым буфера обмена...
Examples in the content include malware extracting or unpacking ZIP, RAR, CAB, tar.gz, and other archived content, such as 'Emotet has used a self-extracting RAR file to deliver modules to victims' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fileless malware used to infect accountants’ machines, deploy a keylogger, capture keystrokes and clipboard contents, monitor cryptographic token connection, and facilitate theft from remote banking systems.
A remote access trojan used to maintain covert control over compromised systems, execute remote commands, download additional malicious tools, and move laterally across victim networks.
Known malware delivered via phishing; campaign targeted multiple sectors in Russia (and referenced alongside 'Sheriff').
Remote access trojan and stealer capable of data theft and providing hands-on keyboard control to attackers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.