Darkcomp is a backdoor malware family linked to the Iranian state-aligned threat actor MuddyWater, also tracked as Seedworm, MERCURY, Static Kitten, Mango Sandstorm, and associated with Iran’s Ministry of Intelligence and Security (MOIS). Multiple sources in the provided content state that Google, Microsoft, and Kaspersky have linked Darkcomp to Seedworm/MuddyWater. Darkcomp is described as legacy MuddyWater tooling and is repeatedly referenced alongside the Stagecomp downloader, which is designed to deploy or download the Darkcomp backdoor. The malware has also been associated with reuse of the code-signing certificate subject “Donald Gay,” which was previously used to sign both Stagecomp and Darkcomp samples and is cited as an attribution link between older MuddyWater tooling and newer malware families such as Fakeset.
In the provided reporting, Darkcomp appears in two main contexts. First, it is part of MuddyWater’s historical malware ecosystem and staging chain, where Stagecomp delivers the Darkcomp backdoor. Second, Rapid7 reported an intrusion campaign assessed with medium to moderate confidence as linked to MuddyWater in which attackers used Microsoft Teams phishing and social engineering to gain access, then used valid credentials, RDP, and curl to deploy payloads including Darkcomp, a malicious Microsoft WebView2 loader intended to disguise traffic, and an encrypted configuration file that sent instructions to Darkcomp. That campaign involved credential harvesting, MFA manipulation, persistence via remote access tooling such as AnyDesk and DWAgent, lateral movement, and theft of sensitive data, while masquerading as a Chaos ransomware incident without actual file encryption.
The content does not provide a full technical breakdown of Darkcomp’s internal command set, persistence mechanism, or protocol details. High-confidence facts directly stated are that Darkcomp is a MuddyWater/Seedworm backdoor, that Stagecomp is used to deploy it, that samples were signed with the “Donald Gay” certificate, and that it was deployed in at least one MuddyWater-linked intrusion together with a malicious WebView2 loader and encrypted configuration. No standalone IOC set specific to Darkcomp beyond the certificate association is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The reuse of code-signing certificates previously associated with MuddyWater malware families, specifically Stagecomp and Darkcomp, creates a direct lineage between legacy and current tooling.
The reuse of code-signing certificates previously associated with MuddyWater malware families, specifically Stagecomp and Darkcomp, creates a direct lineage between legacy and current tooling.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware reportedly tied to Seedworm in public reporting, but the content explicitly notes the name requires verification from the original Broadcom source.
Malware attributed to MuddyWater and referenced as being signed with a code-signing certificate linked to the group.
Backdoor malware deployed after credential theft and RDP access; it received instructions from an encrypted configuration file and was used as part of the intrusion to support espionage activity.
A legacy MuddyWater loader/tool used as part of the actor’s intrusion toolkit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.