Skip to content

Malware

DarkWisp

According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and intelligence gathering.

DarkWisp is a PowerShell malware family operated by Larva-208.

Background

Trend Micro describes DarkWisp as a PowerShell backdoor and reconnaissance tool built for unauthorized access and intelligence collection. It lets attackers siphon off sensitive data while retaining persistent control of the infected host. To build a detailed victim profile, the malware harvests a wide range of system details: it checks whether the user holds administrative rights, tests for corporate domain membership, and scans designated directories and applications for cryptocurrency wallets or VPN software. It additionally records environmental data such as the public IP address, geographic location, installed antivirus products, firewall state, and system uptime, then packages everything into a structured format for transmission to the C&C server.


Source: Malpedia (Fraunhofer FKIE).