Neue Malware-Kampagne nutzt PureCrypter Loader zur Verbreitung von DarkVision RAT

Teilen:

Cybersecurity researchers have disclosed a new malware campaign that leverages a malware loader named PureCrypter to deliver a commodity remote access trojan (RAT) called DarkVision RAT.

The activity, observed by Zscaler ThreatLabz in July 2024, involves a multi-stage process to deliver the RAT payload.

“DarkVision RAT communicates with its command-and-control (C2) server using a custom network protocol via sockets,” security researcher Muhammed Irfan V A said in an analysis.

“DarkVision RAT supports a wide range of commands and plugins that enable additional capabilities such as keylogging, remote access, password theft, audio recording, and screen captures.”

PureCrypter, first publicly disclosed in 2022, is an off-the-shelf malware loader that’s available for sale on a subscription basis, offering customers the ability to distribute information stealers, RATs, and ransomware.

The exact initial access vector used to deliver PureCrypter and, by extension, DarkVision RAT is not exactly clear, although it paves the way for a .NET executable that’s responsible for decrypting and launching the open-source Donut loader.

The Donut loader subsequently proceeds to launch PureCrypter, which ultimately unpacks and loads DarkVision, while also setting up persistence and adding the file paths and process names used by the RAT to the Microsoft Defender Antivirus exclusions list.

DarkVision RAT

Persistence is achieved by setting up scheduled tasks using the ITaskService COM interface, autorun keys, and creating a batch script that contains a command to execute the RAT executable and placing a shortcut to the batch script in the Windows startup folder.

The RAT, which initially surfaced in 2020, is advertised on a clearnet site for as little as $60 for a one-time payment, offering an attractive proposition for threat actors and aspiring cyber criminals with little technical know-how who are looking to mount their own attacks.

Developed in C++ and assembly (aka ASM) for “optimal performance,” the RAT comes packed with an extensive set of features that allow for process injection, remote shell, reverse proxy, clipboard manipulation, keylogging, screenshot capture, and cookie and password recovery from web browsers, among others.

It’s also designed to gather system information and receive additional plugins sent from a C2 server, augmenting its functionality further and granting the operators complete control over the infected Windows host.

“DarkVision RAT represents a potent and versatile tool for cybercriminals, offering a wide array of malicious capabilities, from keylogging and screen capture to password theft and remote execution,” Zscaler said.

“This versatility, combined with its low cost and availability on hack forums and their website, has made DarkVision RAT increasingly popular among attackers.”

The findings coincide with the emergence of a new malware loader dubbed Pronsis Loader that has been put to use in campaigns delivering Lumma Stealer and Latrodectus. The earliest version dates back to November 2023.

“Pronsis Loader is a newly identified malware that bears similarities to the D3F@ck Loader,” Trustwave researchers Cris Tomboc and King Orande said. “Both utilize JPHP-compiled executables, making them easily interchangeable.”

“However, one area they diverge in is their installer approaches: while D3F@ck Loader uses Inno Setup Installer, Pronsis Loader leverages Nullsoft Scriptable Install System (NSIS).”

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:27 am, Juli 1, 2025
Wetter-Symbol 22°C
L: 21° | H: 23°
wenige Wolken
Luftfeuchtigkeit: 78 %
Druck: 1013 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 11 mph 78 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 24°°C 0.2 mm 20% 12 mph 76 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 8 mph 52 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 29°°C 0 mm 0% 10 mph 48 % 1027 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
17° | 22°°C 0.2 mm 20% 13 mph 81 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
21° | 22°°C 0 mm 0% 3 mph 78 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
24° | 27°°C 0 mm 0% 2 mph 69 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 31°°C 0 mm 0% 7 mph 46 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 9 mph 25 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 48 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 6 mph 65 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,648.49
-1.41%
Ethereum(ETH)
€2,087.54
-1.56%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.88
1.35%
Solana(SOL)
€129.32
0.90%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.138181
-2.44%
Shiba Inu(SHIB)
€0.000009
-2.17%
Pepe(PEPE)
€0.000008
-4.91%
Nach oben scrollen