Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

DarkVisionRAT

DarkVisionRAT is a commercial remote access trojan (RAT) sold on underground forums and observed as one of multiple payload families distributed in the active Amadey botnet campaign tagged fbf543 in March 2026. Breakglass Intelligence linked the campaign to a pay-per-install operation that delivered more than 50 payloads over four days and more than 100 tracked samples across 24 malware families over roughly March 1-10, 2026. In the reporting, DarkVisionRAT appeared alongside other remote access tools including XWorm, QuasarRAT, AsyncRAT, and RemcosRAT, and was used for real-time remote control. The campaign also deployed stealers, loaders, coin miners, and abused legitimate RMM tools such as ConnectWise, DattoRMM, Atera, GoToResolve, and N-able for persistence, indicating DarkVisionRAT was one component of a broader criminal distribution ecosystem rather than the sole objective. High-confidence delivery context places DarkVisionRAT in the Amadey fbf543 distribution chain, including activity on March 6, 2026, when the campaign deployed XWorm, SantaStealer, NirCmd, a ConnectWise MSI, AsyncRAT, HijackLoader, and DarkVisionRAT. Associated infrastructure for the broader campaign included Amadey C2 sys32[.]cc, backend payload hosting at labinstalls[.]info on 158.94.211.222, and initial delivery from qpgroup[.]top. The operation was assessed with low-to-medium confidence as financially motivated and likely linked to the CIS or Russian-speaking cybercrime ecosystem. No DarkVisionRAT-specific IOCs, persistence mechanisms, or internal technical details beyond its role as a commercial RAT and its deployment for remote control were directly provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

MITRE ATT&CK Mapping ... Command and Control Ingress Tool Transfer T1105 Amadey downloads 50+ payloads to infected hosts

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.