DarkVNC is a Windows remote-access malware family centered on hidden VNC functionality that allows an operator to interact with an infected system remotely. It is commonly described as a backdoor trojan and has been observed as a follow-on payload in financially motivated intrusion chains rather than as a standalone initial-access tool. Reported activity links DarkVNC to multi-stage infections involving loaders and banking malware such as IcedID and QakBot, as well as broader crimeware delivery ecosystems including TrickGate-wrapped payloads and campaigns that also deploy Cobalt Strike, AZORult, Remcos, and cryptocurrency-focused malware.
Operationally, DarkVNC provides covert remote control over compromised Windows hosts using VNC-style communications, enabling post-compromise interactive access. Public reporting also associates it with hidden VNC or hVNC-style behavior, and some analyses note code overlap with other hVNC-based malware families, which can complicate labeling. DarkVNC traffic has repeatedly been observed after IcedID infections, including campaigns attributed to TA551, also known as Shathak or Monster Libra, and after QakBot compromise. It has also appeared in financially motivated campaigns documented by Cisco Talos and in activity associated with Tor2Mine. In some intrusion chains, DarkVNC is selected conditionally by a loader when the victim lacks administrative privileges, indicating use as a practical remote-access fallback within modular malware operations.
Distribution has been tied to multiple delivery mechanisms through upstream malware or compromised distribution channels. Observed infection chains include malspam with malicious Office documents, phishing-delivered ZIP or ISO archives containing shortcuts and script-based loaders, and trojanized software downloads from a compromised legitimate website. DarkVNC has also been referenced as a payload delivered by IcedID and by packer or crypter services such as TrickGate. Targeting in observed campaigns is broad and financially motivated, with victims spanning enterprise environments and sectors such as manufacturing, education, healthcare, finance, telecommunications, legal services, charities, and other businesses.
DarkVNC should be distinguished from IcedID BackConnect VNC and Anubis VNC activity. Some reporting explicitly corrected earlier misidentification of IcedID-related VNC traffic as DarkVNC, and other analyses caution that detections labeled as DarkVNC may sometimes reflect shared hVNC code rather than definitive family attribution. High-confidence characterization supports DarkVNC as a Windows backdoor used for covert remote access in crimeware intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign included the use of a variant of AZORult, an information-stealing malware; as well as the RAT Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
Today's diary reviews an example of Monster Libra pushing IcedID on Thursday 2022-08-11, and that IcedID infection led to Dark VNC activity and Cobalt Strike.
We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The ISO image seems to have been downloaded compressed with ZIP, possibly encrypted with a password, which indicates it's primarily spread via email.
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
All strings, including the entire command line for the downloader PowerShell code are encrypted with a static byte key, different for each string, which also gets decrypted during the execution.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access tool/module referenced as part of BackConnect infrastructure used by QakBot-linked actors.
Referenced as an hVNC-style capability that Xeno RAT can emulate/incorporate for remote access to infected systems.
DarkVNC is mentioned only as an incorrect earlier identification of the observed VNC traffic, later corrected to Anubis VNC.
Mentioned only as a possible code-overlap or detection-label reference for the analyzed sample, not as the primary malware under discussion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.