Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DarkRaaS

Also known as: root access, ArechClient2, UNC788, CALANQUE, Mint Sandstorm, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, a botnet

Description

DarkRaaS is a highly adaptable threat actor centered around revenue generation through the sale of unauthorized system access. The group builds or rents botnets, often composed of compromised cloud instances and legacy Windows machines, which provide command‑and‑control (C2) channels for phishing campaigns and distributed denial‑of‑service (DDoS) attacks. Leveraging legitimate third‑party web services such as email, cloud storage, and container registries, DarkRaaS can exfiltrate data covertly while bypassing traditional perimeter controls. Persistence is achieved through a mix of techniques that include hijacking Windows service binaries to execute malicious code with SYSTEM privileges, deploying backdoored container images in public registries, and creating local or domain user accounts. The actor also uses service‑hijacking as well as disabling native backup services to inhibit incident recovery. Operationally, DarkRaaS systematically targets sectors where regulated data is abundant—defense, media, finance, manufacturing, and government—while exploiting MFA weaknesses, vulnerable software, and unused API endpoints. The use of cloud infrastructure allows them rapid scaling and a low‑cost footprint, which contributes to their ability to carry out repeated campaigns over several months. Tactics span the ATT&CK matrix from initial access via phishing and exploitation of remote services through C2 channels that leverage legitimate web APIs, to stealthy exfiltration with encrypted cloud storage. Their goal remains monetary gain, monetizing compromised hosts by selling VPN or remote desktop access for prices up to $25,000.

Goals & Targeting

Targeted Sectors

Defense
Media
Financial services
Manufacturing
Government
Information technology

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

DarkRaaS is a financially motivated threat actor that sells illicit remote access and compromised credentials through cloud infrastructure, botnets, and third‑party web services. The group leverages sophisticated persistence techniques such as container image backdooring and service hijacking to maintain long‑term footholds in targeted organizations across the defense, media, finance, manufacturing, and government sectors. Recent activity indicates a focus on Israel, UAE, Turkey, and South America, with an operational tempo that blends large‑scale phishing, credential theft, and distributed denial‑of‑service attacks.

Goals & Targeting

DarkRaaS’s strategic objective is the continuous monetization of infiltrated networks through sale of persistent remote access. The actor prioritizes high‑value targets that host regulated or sensitive data—government agencies, defense contractors, media outlets, financial institutions, and manufacturing firms—and that exhibit weak multi‑factor authentication or under‑patched infrastructure. By exploiting cloud services and service hijacking, they aim to remain undetected while maximizing the number of hosts sold per campaign.

Enhanced Description

Key Capabilities

  • Acquire cloud infrastructure for command and control
  • Build or rent botnets for persistence and distributed attacks
  • Use compromised email accounts for phishing campaigns
  • Leverage third‑party web services for C2 and data exfiltration
  • Create local and domain user accounts to maintain privilege

MITRE ATT&CK Tactics

Initial Access
Command and Control
Exfiltration
Account Discovery
Privilege Escalation
Persistence
Lateral Movement
Execution
Defense Evasion
Impact

ATT&CK Techniques

T1037
T1557
T1583
T1123
T1547
T1119
T1115
T1530
T1082
T1071
T1140
T1219
T1036
T1055
T1010
T1560
T1185
T1580
T1217
T1595
T1548
T1087
T1059
T1020
T1083
T1612
T1497
T1098
T1566
T1110
T1531
T1027
T1486
T1671
T1197
T1650
T1651
T1134
T1018
T1105
T1566.001
T1505.002
T1071.001
T1048
T1136.001
T1136.002
T1499
T1210
T1546.011
T1036.004

Software / Tooling

Sunburst
Havex RAT
HawkEye Keylogger
MailSniper
Emotet
SocGholish
DarkSide

Campaigns & Victims

The actor appears to operate in staged waves. Initially, it acquires or rents compromised cloud resources, then builds botnets that serve as C2 backbones and platforms for large‑scale phishing attacks. Subsequent waves involve exploitation of software vulnerabilities, lateral movement, and the deployment of backdoored container images to maintain persistence. DarkRaaS demonstrates a rapid operational tempo—launching campaigns within weeks of each other—and consistently targets entities with strong multi‑factor authentication but weak endpoint security or under‑patched services. Notable operations include a March 2024 data exfiltration against a UAE oil‑and‑gas company, where attackers leveraged a compromised public container registry to plant backdoored images that delivered C2 payloads.

IOC Patterns

  • Use of legitimate third‑party web service accounts for command and control or exfiltration
  • Creation of new local/domain user accounts with elevated permissions
  • Denial‑of‑service targeting DNS or web services
  • Remote exploitation of software vulnerabilities
  • Hijacking Windows service binaries to run malicious code
  • Deployment of malicious cloud/container images in public registries

Recommended Actions

  • Implement MFA across all cloud and email accounts, using strong anti‑spoof controls
  • Monitor outbound traffic for anomalous botnet patterns and known C2 domains
  • Block IP ranges associated with illicit or rented botnets
  • Conduct phishing awareness training focused on spearphishing via legitimate web services
  • Audit creation of local and domain user accounts to detect unauthorized accounts
  • Apply timely patches for all software to close remote exploitation vectors
  • Enable file integrity monitoring on critical Windows service binaries
  • Segment networks to isolate cloud deployments and limit lateral movement
  • Require signing or provenance validation of container images before deployment
  • Implement DDoS mitigation such as rate limiting, WAF, and traffic anomaly detection

Suggested Tags

botnet
cloud infrastructure abuse
compromised email
phishing
exfiltration over web service
third‑party web‐service C2
cloud storage exfiltration
DDoS attack
account compromise
service hijacking
remote service exploitation
vulnerability exploitation
privilege escalation
container image backdooring
persistence
defense evasion
traffic spoofing
MFA bypass
reflection DDoS

Confidence Assessment

The confidence in the core capabilities and tactics of DarkRaaS is high, owing to repeated evidence across multiple reports. Uncertainty remains regarding the exact size of their infrastructure, precise alias mapping (some sources conflate them with other groups), and the scope of their cloud‑based operations because much activity occurs over encrypted channels. Gaps also exist around the full spectrum of malware families they deploy beyond the identified backdoors and RATs.

ATT&CK Techniques

Lateral Movement
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.malwarebytes.com — Cited by web research for: root access
  2. attack.mitre.org — Cited by web research for: services
  3. www.recordedfuture.com — Cited by web research for: T1497
  4. attack.mitre.org — Cited by web research for: PowerShell
  5. redcanary.com — Cited by web research for: SocGholish
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhoven.de/details/win.havex_rat — Cited by AI analysis.
  8. https://malpedia.caad.fkie.fraunhofer.de/details/win.hawkeye_keylogger — Cited by AI analysis.
  9. https://www.darktrace.com/resources/annual-threat-report-2026 — Cited by AI analysis.

Intel Summary

50

Techniques

45

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Data Exfiltration
Government Targeting
APT Group
Cyber Espionage
Financial Gain
Geopolitical Targeting
Oil & Gas Sector
botnet
cloud infrastructure abuse
compromised email
phishing
exfiltration over web service
third‑party web‐service C2
cloud storage exfiltration
DDoS attack
account compromise
service hijacking
remote service exploitation
vulnerability exploitation
privilege escalation
container image backdooring
persistence
defense evasion
traffic spoofing
MFA bypass
reflection DDoS

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.