Researchers reported multiple phishing campaigns delivering the DarkWatchman remote access trojan through Russian-themed lures, including a fake CryptoPro CSP site and messages imitating military conscription summons. Victims were directed to download password-protected or self-extracting archives that launched a downloader, dropped an obfuscated JavaScript backdoor, and decrypted a PowerShell-based keylogger. The malware collected keystrokes, clipboard contents, smart card data, and host information, then exfiltrated the data to command-and-control infrastructure.
DarkWatchman stood out for storing configuration data, payload components, and stolen information in the Windows Registry rather than on disk, complicating detection and forensic recovery. The malware executed via wscript.exe, added Windows Defender exclusions, established persistence with Task Scheduler using generated task names, deleted installation artifacts, and in some cases removed volume shadow copies when running with elevated privileges. Reporting also linked the malware’s delivery and operation to heavy use of obfuscation and decryption techniques, including encrypted blobs and Base64-encoded PowerShell, consistent with MITRE ATT&CK T1140 behavior.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Cyble reported that DarkWatchman was first detected in 2021. This establishes the earliest explicit date tied to the malware family in the provided references.
IBM X-Force reported a phishing campaign, tracked as Hive0117, that imitated conscription summons to deliver DarkWatchman malware. The analysis described downloader files retrieving an SFX archive that installed an obfuscated JavaScript backdoor and registry-stored keylogger components.
Cyble Research and Intelligence Labs identified a phishing website impersonating CryptoPro CSP, using the domain cryptopro-download[.]one to distribute DarkWatchman to primarily Russian users. The campaign delivered a password-protected archive containing an SFX installer that deployed the JavaScript RAT and encrypted keylogger.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securityintelligence.com
Open sourcecyble.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.