DarkComet RAT is a Windows remote access trojan that provides covert remote control and surveillance capabilities on compromised systems. Originally developed as a commercially available administration tool and later discontinued, it has remained widely circulated in underground ecosystems and continues to be repurposed in criminal and politically motivated operations. DarkComet has been associated with espionage-oriented use, including reporting linking it to surveillance of Syrian dissidents, and it has also appeared in commodity malware campaigns using contemporary social-engineering themes such as cryptocurrency software lures.
DarkComet supports classic RAT functionality including remote command execution, keylogging, credential theft, remote desktop control, webcam-enabled spying, file theft, and process injection into legitimate processes. Observed samples have stored captured keystrokes locally before operator retrieval or exfiltration. Persistence has been achieved by copying the malware to user-accessible application data locations under deceptive names and configuring automatic execution at logon through Windows autorun mechanisms. Some observed samples were packed or obfuscated, including with UPX, to hinder static analysis and detection.
Documented delivery has included lure-based distribution in archives masquerading as legitimate Bitcoin wallet or trading utilities, relying on user execution of the disguised program. DarkComet is best understood as a long-lived, reusable surveillance RAT whose continued effectiveness stems from low barriers to reuse, broad remote-control features, and operators’ ability to wrap it in topical social-engineering themes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
직접적인 연관 관계는 확인되지 않지만 수집된 샘플들 중에서 동일한 패커를 이용해 패킹된 DarkComet RAT 악성코드도 확인된다.
A new piece of old computer spyware, known as DarkComet RAT, was found cleverly hidden inside a file that looked exactly like a legitimate Bitcoin wallet or trading program.
A new piece of old computer spyware, known as DarkComet RAT, was found cleverly hidden inside a file that looked exactly like a legitimate Bitcoin wallet or trading program.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"delivered inside a compressed RAR file, which is a common trick used by attackers to evade security filters"
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used for surveillance and data theft. In this campaign it is disguised as a Bitcoin wallet utility, packed with UPX, establishes persistence by copying itself to %AppData%\Roaming\MSDCSC\explorer.exe and creating a Run key, performs keylogging (stores logs in 'dclogs'), uses process injection (e.g., into notepad.exe), and beacons to a C2 server over TCP.
Remote access trojan that provides covert remote control of an infected system, including keylogging, file theft, webcam spying, and remote desktop control. In the described campaign it is delivered via a RAR archive containing a fake Bitcoin wallet executable, establishes persistence via an autostart entry, and beacons to a DDNS C2 (kvejo991.ddns.net:1604) while logging keystrokes to a local 'dclogs' folder to steal credentials (including crypto wallet access).
Remote access trojan with extensive espionage capabilities, discussed as surveillance malware used against targets in Syria.
Remote access trojan with extensive espionage capabilities, cited here as an example of surveillance malware being repurposed for malicious political repression.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.