Skip to main content

Darkhole Backdoor

Darkhole is a backdoor primarily used to steal user credentials which was first detected in 2012. The malware is targeted against Windows systems.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Darkhole is a backdoor primarily used to steal user credentials which was first detected in 2012. The malware is targeted against Windows systems.

Affected platforms

The following platforms are known to be affected:

Threat details

It is distributed by malspam, wateringhole and multi-stage malware attacks. Darkhole is capable of creating a listening port and communicating details saved in browser password managers.

The malware predominantly relies on user interaction in social engineering attacks in the infection chain and has little advancements since its initial deployment. If infected, businesses would face risks to the confidentiality of sensitive data and could be susceptible to subsequent further malware attacks using Darkhole’s backdoor capabilities.

The malware targets Windows 2000, Windows XP, Windows Server 2003 machines and is also known as VirTool:Win32/VBInject (Microsoft); BackDoor-AMQ.dr (McAfee); or Backdoor.Win32.DarkHole.gm, Backdoor.Win32.DarkHole.gm (Kaspersky).

Once present on the targeted device, the malware uses memory hollowing as a simplistic anti-detection method. It unpacks several executables under the following file structure: %WINDIR%\Debug\result.dark %WINDIR%\Debug\fipst.exe.
Darkhole then makes changes to registry keys and system directory. It then makes additions to the system directory to authorise its own activity through the Windows firewall. The malware scrapes device and network information and then opens a listening port using the sfvin.exe on port 1080. This allows for a communication channel to be established to the C2 infrastructure, whereby instructions or additional malware can be received and gleaned data sent. Darkhole attempts to read the host’s browser password manager local database and credentials used in popular FTP client applications. Once obtained, these are sent to a C2 node, likely as part of a HTTP GET request.


Remediation steps

Type Step
• Update antivirus software and other security products to the latest version.
• If infected, users should change all credentials (including banking details) saved in browser password managers.
• Social engineering and user interaction is needed for infection. Regular and appropriate employee training is recommended.

Last edited: 17 February 2020 12:41 pm