DarkComet is a Win32 backdoor/remote access trojan (RAT) for Windows NT-based systems designed to remotely control or administer an infected computer. Reported capabilities include collecting host information such as the username, interpreting remote commands, process and service management, remote desktop access, file management, registry modification, execution of remotely sent JavaScript and VBScript, webcam image capture, microphone/audio capture, clipboard theft, SOCKS proxying, IP/port redirection, downloading/sending/executing files, and system shutdown or reboot. It can log keystrokes locally in %APPDATA%dclogs using YY-MM-DD.dc filenames and can send those logs to a remote FTP server. The malware stores encrypted connection parameters in the executable. Observed registry-related behavior includes adding values under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System with EnableLUA="0" and HKEY_CURRENT_USER\Software\DC3_FEXEC, and it can disable Security Center/antivirus-related functions.
DarkComet has been delivered in multiple intrusion contexts. The content explicitly associates it with spearphishing campaigns using malicious documents, including activity attributed to ModifiedElephant, which targeted human rights activists, defenders, academics, journalists, and lawyers in India and used NetWire and DarkComet as primary RAT payloads. It is also referenced in Operation Transparent Tribe-related activity, where older DarkComet samples were delivered via India-themed lures. Separately, Kaspersky reported DarkKomet/DarkComet-family backdoors distributed through malicious Steam Workshop Wallpaper Engine application wallpapers since late 2025, primarily affecting gamers in China. In analyzed samples, a backdoor named Synaptics.exe was dropped to C:\ProgramData\Synaptics, sometimes alongside a tampered AggregatorHost.dll and ._cache_GAME1.exe while a decoy game executed. In that campaign, the malicious DLL searched for the Steam client, hijacked active Steam sessions, and exfiltrated stolen session data to attacker-controlled infrastructure including 120.48.156.17/ey.php. Additional infrastructure and related indicators mentioned in the content include 202.144.192.29, brightly.to, a Dropbox-hosted Synaptics.rar, multiple Steam Workshop item URLs, and MD5 hashes such as 07e44ffcffde46ad96eb9c018bed6193, 95856f2ce428c728d9781d3296558068, af080780cca2acd1d082ce01e7cc346a, and c133c3dd9f7d6934598025047df41abf.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
"...spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158..." | "...off-the-shelf remote administration tools (RATs) and downloaders, such as DarkComet and Bozok."
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .
DarkComet (Backdoor.Breut): Another commodity RAT used to open a backdoor on an infected computer and steal information.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs.
The program performs the following functions: Running JavaScript / VBScript scripts sent remotely.
The program performs the following functions: Running JavaScript / VBScript scripts sent remotely.
Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs.
The app supports four wallpaper types, and one of them, the "application wallpaper," is a standalone executable Windows program that runs as the desktop background. That also makes it a pathway for third-party code to execute on a user's machine, which is exactly what attackers exploited.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The program performs the following functions: ... Managing system services.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The program performs the following functions: Saving keystrokes to a file ... Sending keystroke logs to a remote FTP server.
That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server.
The program performs the following functions: Obtaining a list of windows.
The program performs the following functions: ... Controlling processes.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The program performs the following functions: Saving keystrokes to a file ... Sending keystroke logs to a remote FTP server.
The program performs the following functions: Capturing clipboard contents.
The program performs the following functions: Capturing video and audio from a webcam or microphone.
That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server.
The program performs the following functions: Acting as a SOCKS proxy server.
Indicators of Compromise (IOC) List Domain/URL: http://202.144.192.29/download2/Themes2.zip ... http://brightly.to/download2/Themes2.zip ... https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 ... https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/RAT payload dropped via malicious Steam Wallpaper Engine packages to hijack Steam sessions and support account theft and further propagation.
Remote access trojan/backdoor delivered via malicious Steam Workshop Wallpaper Engine application wallpapers; used to establish backdoor access on infected systems.
Backdoor/RAT family deployed via malicious Wallpaper Engine projects; in the described sample it was installed under the name Synaptics.exe as part of the infection chain.
Backdoor malware used in the malicious Steam Workshop wallpaper campaign to execute on victims' PCs and enable unauthorized access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.