DarkWatchman

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[DarkWatchman](https://attack.mitre.org/software/S0673) is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.(Citation: Prevailion DarkWatchman 2021)

Associated Techniques (34)
ID ATT&CK Tactics
T1005 Data from Local System -
T1010 Application Window Discovery -
T1012 Query Registry -
T1027.004 Compile After Delivery -
T1027.010 Command Obfuscation -
T1027.011 Fileless Storage -
T1027.015 Compression -
T1033 System Owner/User Discovery -
T1036 Masquerading -
T1047 Windows Management Instrumentation -
T1053.005 Scheduled Task -
T1056.001 Keylogging -
T1059.001 PowerShell -
T1059.003 Windows Command Shell -
T1059.007 JavaScript -
Metadata
ID: 290
Created: 13/01/2026 17:48
Updated: 21/04/2026 16:00