Also known as: root access, ArechClient2, UNC788, CALANQUE, Mint Sandstorm, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, a botnet
DarkRaaS is a highly adaptable threat actor centered around revenue generation through the sale of unauthorized system access. The group builds or rents botnets, often composed of compromised cloud instances and legacy Windows machines, which provide command‑and‑control (C2) channels for phishing campaigns and distributed denial‑of‑service (DDoS) attacks. Leveraging legitimate third‑party web services such as email, cloud storage, and container registries, DarkRaaS can exfiltrate data covertly while bypassing traditional perimeter controls. Persistence is achieved through a mix of techniques that include hijacking Windows service binaries to execute malicious code with SYSTEM privileges, deploying backdoored container images in public registries, and creating local or domain user accounts. The actor also uses service‑hijacking as well as disabling native backup services to inhibit incident recovery. Operationally, DarkRaaS systematically targets sectors where regulated data is abundant—defense, media, finance, manufacturing, and government—while exploiting MFA weaknesses, vulnerable software, and unused API endpoints. The use of cloud infrastructure allows them rapid scaling and a low‑cost footprint, which contributes to their ability to carry out repeated campaigns over several months. Tactics span the ATT&CK matrix from initial access via phishing and exploitation of remote services through C2 channels that leverage legitimate web APIs, to stealthy exfiltration with encrypted cloud storage. Their goal remains monetary gain, monetizing compromised hosts by selling VPN or remote desktop access for prices up to $25,000.
Targeted Sectors
Executive Summary
DarkRaaS is a financially motivated threat actor that sells illicit remote access and compromised credentials through cloud infrastructure, botnets, and third‑party web services. The group leverages sophisticated persistence techniques such as container image backdooring and service hijacking to maintain long‑term footholds in targeted organizations across the defense, media, finance, manufacturing, and government sectors. Recent activity indicates a focus on Israel, UAE, Turkey, and South America, with an operational tempo that blends large‑scale phishing, credential theft, and distributed denial‑of‑service attacks.
Goals & Targeting
DarkRaaS’s strategic objective is the continuous monetization of infiltrated networks through sale of persistent remote access. The actor prioritizes high‑value targets that host regulated or sensitive data—government agencies, defense contractors, media outlets, financial institutions, and manufacturing firms—and that exhibit weak multi‑factor authentication or under‑patched infrastructure. By exploiting cloud services and service hijacking, they aim to remain undetected while maximizing the number of hosts sold per campaign.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor appears to operate in staged waves. Initially, it acquires or rents compromised cloud resources, then builds botnets that serve as C2 backbones and platforms for large‑scale phishing attacks. Subsequent waves involve exploitation of software vulnerabilities, lateral movement, and the deployment of backdoored container images to maintain persistence. DarkRaaS demonstrates a rapid operational tempo—launching campaigns within weeks of each other—and consistently targets entities with strong multi‑factor authentication but weak endpoint security or under‑patched services. Notable operations include a March 2024 data exfiltration against a UAE oil‑and‑gas company, where attackers leveraged a compromised public container registry to plant backdoored images that delivered C2 payloads.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core capabilities and tactics of DarkRaaS is high, owing to repeated evidence across multiple reports. Uncertainty remains regarding the exact size of their infrastructure, precise alias mapping (some sources conflate them with other groups), and the scope of their cloud‑based operations because much activity occurs over encrypted channels. Gaps also exist around the full spectrum of malware families they deploy beyond the identified backdoors and RATs.
No campaigns linked yet.
No observed data linked yet.
50
Techniques
45
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics