Cisco Talos reported that attackers have used Dark Utilities, a command-and-control-as-a-service (C2aaS) platform launched in early 2022, to run malware campaigns against both Windows and Linux systems. The service provides remote access, arbitrary command execution, distributed denial-of-service capabilities, and Monero mining, while distributing payloads for Windows, Linux, and Python environments. Researchers said the platform relies on IPFS-hosted binaries to make payload delivery more resilient against takedowns and is promoted through Telegram, Discord, Tor, and clearnet infrastructure.
The malware associated with Dark Utilities can establish persistence, self-update, execute shell commands and Python code, launch Layer 4 and Layer 7 DDoS attacks, and deploy XMRig miners through the Hashvault pool. The reporting also links the ecosystem to the persona inplex-sys, assessed likely to be based in France, and highlights how the service lowers the barrier to entry for cybercriminals. A related malware reference identifies Kinsing, a Linux-focused malware family, underscoring the broader risk that commodity botnet and cryptomining tooling poses to internet-exposed systems.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Shortly after launch, the persona inplex-sys advertised Dark Utilities in the Lapsus$ Group Telegram channel. Talos assessed that inplex-sys created and managed the platform.
Dark Utilities, a command-and-control-as-a-service platform offering remote access, command execution, DDoS, and Monero mining features, was released in early 2022. The service was marketed via clearnet, Tor, Telegram, and Discord and offered premium access for 9.99 euros.
Talos assessed that the persona inplex-sys created and currently manages Dark Utilities and found indications the operator is likely located in France despite a Doxbin entry claiming Germany. The report also documented the platform's use of IPFS-hosted binaries and Discord-backed authentication.
Dark Utilities expanded support to ARM64 and ARMV71 architectures, broadening targeting to embedded devices such as routers, phones, and IoT systems. This marked an escalation beyond Windows, Linux, and Python-based payload support.
Researchers observed malware samples in the wild using Dark Utilities-generated command strings in PowerShell and Bash scripts to retrieve and execute payloads for remote access and cryptocurrency mining. Multiple distinct account strings in the samples indicated that more than one threat actor was likely using the platform.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 61 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.