DarkTrack RAT is a Windows remote access trojan used in phishing-led intrusion campaigns to provide covert control of compromised systems. It has been observed alongside other commodity and criminal malware families in operations targeting Russian organizations, including scientific, industrial, governmental, and defense-related entities, as well as in financially motivated activity affecting Ukrainian organizations. Reported campaigns show it being delivered after victims open malicious executable content disguised as documents, with decoy files displayed to reduce suspicion. It has also been noted as a payload dropped via PureCrypter and as part of broader malware sets that included tools such as Remcos, Sectop RAT, Lumma Stealer, and Mars Stealer.
DarkTrack RAT is associated in the available reporting with activity attributed to Sticky Werewolf and with campaigns imitating Sticky Werewolf tradecraft. In these operations, phishing emails or phishing links were used for initial access, often themed around official or legal documents and tailored to regional targets. The malware’s role is to establish remote interactive access for post-compromise operations. High-confidence reporting in the supplied material supports its classification as a remote access trojan, but does not provide a sufficiently corroborated capability breakdown specific to DarkTrack RAT beyond remote access functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
...в которых часто встречаются такие инструменты, как трояны удаленного доступа Darktrack RAT и Ozone RAT...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Упоминается как альтернативный RAT, устанавливаемый после открытия вредоносного файла в фишинговой цепочке первоначального доступа.
Remote access trojan used for comprehensive data theft and remote control; delivered via PureCrypter in the described attack chain.
Remote access trojan cited as one of the tools frequently used by Sticky Werewolf in phishing campaigns.
Named RAT in the toolset attributed to UAC-0050, used for remote control of victim machines to support theft and espionage objectives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.