Security researchers documented how banking trojans and follow-on intrusion frameworks used reverse VNC backdoors to give operators interactive access to compromised Windows systems. Analysis of IcedID and Qakbot described malware families and backdoor variants including Dark Cat, Anubis, and Keyhole, while a separate Ursnif intrusion showed VNC-enabled hands-on-keyboard activity alongside Cobalt Strike beacons, host and domain discovery, clipboard interaction, and screenshot collection through external image-hosting links.
The reporting also tied these capabilities to real intrusion chains. In the Contact Forms campaign, victims were lured with fake DMCA-themed messages that delivered an ISO containing a shortcut, JavaScript, and DLLs that led to IcedID infection, followed by traffic linked to DarkVNC and multiple Cobalt Strike payloads. Supporting this research, the PCAPeek proof-of-concept was released to reconstruct reverse VNC sessions from packet captures, allowing analysts to recover clipboard files, JPEG frames, and MJPEG video from traffic associated with IcedID and Qakbot backdoors.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
A second Cobalt Strike activity window began on 2021-12-14 at 15:33 UTC and continued through the end of the packet capture at 17:17 UTC. This stage retrieved HI1FA3OB3N7D9.dll over HTTP and generated HTTPS traffic to bqtconsulting.com.
The first observed Cobalt Strike activity began on 2021-12-14 at 06:30 UTC and lasted until 11:55 UTC. This stage retrieved musicbee.dll over HTTP and generated HTTPS traffic to api.musicbee.getlist.destinycraftpe.com.
DarkVNC activity was observed starting on 2021-12-13 at 23:33 UTC following the IcedID infection. The traffic used encoded or encrypted TCP communications to 88.119.161.88 on port 8080.
An infection run tied to the Contact Forms campaign began on 2021-12-13 at 21:45 UTC, using a fake DMCA-themed "Stolen Images Evidence" lure that delivered an ISO file from a Google-hosted URL. When opened, the ISO exposed a shortcut that executed a hidden JavaScript file and DLL, resulting in IcedID infection.
The Contact Forms campaign, which abused website contact forms to send malicious links disguised as legal complaints, had consistently switched from ZIP archives to ISO files by 2021-11-30. The campaign had previously delivered BazarLoader and Sliver before shifting to IcedID.
The Ursnif analysis reported using PCAPeek to reconstruct some of the malware's VNC traffic. This reconstruction enabled recovery of threat actor clipboard data, including screenshot links and admin-panel-related paths and parameters.
A published analysis described an Ursnif intrusion that performed automated host and domain discovery, exfiltrated reconnaissance data, and later used Cobalt Strike beacons for command-and-control. The intrusion also involved hands-on-keyboard activity, VNC-based remote access, and use of LightShot screenshot links hosted on prnt.sc.
A GitHub repository for PCAPeek was published as a proof-of-concept utility to reconstruct reverse VNC traffic from packet captures associated with IcedID and Qakbot VNC backdoors. The tool can output reconstructed clipboard files, JPEG frames, and MJPEG videos, and credits prior research by Brad Duncan and Erik Hjelmvik.
NVISO published research focused on IcedID and Qakbot VNC backdoors under the names Dark Cat, Anubis, and Keyhole. The reference establishes public reporting on these reverse VNC backdoor variants.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 68 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
kostas-ts.medium.com
Open sourcegithub.com
Open sourceblog.nviso.eu
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.