RAT
DarkVision RAT
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020.
DarkVision RAT is a Windows rat.
Background
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first seen in 2020. Built in C/C++ and assembler, it has become popular thanks to its low price and wide feature set, which includes keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. A July 2024 campaign was observed spreading DarkVision_RAT with PureCrypter acting as the loader. The RAT talks to its command and control server over a custom socket-based network protocol and relies on evasion and privilege-escalation methods such as DLL hijacking, self-elevation, and process injection. Through its broad selection of commands and plugins it can extend its functionality further, adding capabilities such as keylogging, remote access, password theft, audio recording, and screenshot capture.
Source: Malpedia (Fraunhofer FKIE).