Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 2 IP / 3 hostnames
DarkComet is a Windows remote access trojan and backdoor used to remotely control compromised systems.
Profile source: Mallory opens in a new tabDarkComet
DarkComet is a Windows remote access trojan and backdoor used to remotely control compromised systems. It is a long-established commodity RAT associated with surveillance, credential and data theft, and general post-compromise system administration by attackers. The malware supports remote command execution and broad host control functions, including process and service management, file transfer and file manipulation, registry modification, remote desktop access, script execution, system reboot or shutdown, and proxying capabilities. Documented collection features include keylogging, clipboard theft, webcam capture, host user discovery, and exfiltration of stolen data such as keystroke logs.
DarkComet has been observed in both opportunistic and targeted intrusion activity. It has been used by threat actors in spearphishing campaigns with malicious documents, including operations attributed to ModifiedElephant and activity associated with Transparent Tribe reporting. It has also appeared in more recent malware distribution campaigns abusing Steam Workshop and Wallpaper Engine application wallpapers, where weaponized wallpaper packages silently installed a DarkComet-family backdoor while presenting benign-looking content to the victim. In those campaigns, DarkComet was one of several payloads delivered to gamers, alongside infostealers, loaders, cryptominers, and ransomware, with Steam account theft and session abuse as prominent objectives.
DarkComet targets Windows systems and is commonly characterized as a RAT/backdoor family rather than a specialized stealer. Its functionality makes it suitable for persistent access, surveillance, and follow-on payload delivery, and it remains a recognizable malware family in incident response despite its age.
C2 tracking
Derp observations, rolling seven-day window
Samples
04b48e191f9c2ef4177320b9a8886e1fd4a2d608e5b3d99e5f3c7954c3966fa1 0e8336ed51fe4551ced7d9aa5ce2dde945df8a0cc4e7c60199c24dd1cf7ccd48 7f391ba28ef7e543bd9c78680f6be819d648e4a1ab4d8d3a0b148342756229ce 0d568ed3bc1baf9905375b961b7c1d0240b73fb0edca2b0763f6d1b9fa86a1cb a6b24ddaa58a3ab66d4a3e4a52f073d47a226982b3a35c5a8134e9aa9f385cf5 ebd2771a7425cdbf188f8616669d39fff4a721e93f9fbaaa03b75483a9827f74 06f2eeb55cccacafce8d0426dede317239e3453b7c7bb08232f25175be3470a6 Reported operators
Payload (older): 07e44ffcffde46ad96eb9c018bed6193 (DarkComet)
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .
DarkComet (Backdoor.Breut): Another commodity RAT used to open a backdoor on an infected computer and steal information.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
“ALUMINUM SARATOGA uses many openly available tools for its operations, including… DarkComet…”
File-based ... Trojan.Darkcomp ...
Exploited software
MITRE ATT&CK
Reporting
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.