Skip to content

DarkComet

DarkComet is a Windows remote access trojan that provides an operator with broad control over an infected system.

Profile source: Mallory opens in a new tab

DarkComet

Family profile

DarkComet is a Windows remote access trojan that provides an operator with broad control over an infected system. It is widely known as a commodity RAT and has been used both by criminal operators and in targeted intrusions. Reported capabilities include remote administration, process enumeration, script execution, keylogging, collection of victim username information, file transfer, and persistence through Windows autostart mechanisms. It has also been observed using masquerading tactics by adopting names resembling legitimate Windows or security-related software.

DarkComet commonly establishes persistence by creating Registry-based autorun entries and has also been associated with Startup-folder persistence. Observed behavior includes modification of Windows Registry values, including changes intended to support execution at logon or startup and, in some cases, weaken security settings. It can enumerate active processes on the host and gather basic host and user context for operator awareness.

The malware has been linked in public reporting to multiple threat actors and intrusion sets, including use by APT33 and references alongside Lazarus-related tooling, though DarkComet itself is broadly available and not exclusive to any single actor. It has also appeared in malware repositories and has been delivered by other malware families and downloaders. Public reporting further notes use of cloud tunneling services such as ngrok to conceal command-and-control infrastructure. DarkComet has been observed in phishing-related ecosystems and in targeted attack reporting affecting government and regional victims, particularly within older Windows-centric intrusion activity.

Capabilities

  • Defense Evasion
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
4 IP / 17 hostnames

Leading locations

  • FR3
  • GB3
  • TR3
  • ES1
  • MX1
  • NL1
  • UA1
  • US1

Leading providers

  • Oracle Corporation3
  • OOO GETWIFI2
  • Turk Telekomunikasyon Anonim Sirketi2
  • ALEXHOST SRL1
  • BrainStorm Network, Inc1
  • Google LLC1

Infrastructure traits

  • Hosting 7
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
APT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

Aluminum Saratoga

ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat

ModifiedElephant

The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

Molerats

google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .

APT38

Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"

Exploited software

Vulnerabilities linked to DarkComet

5 CVEs

MITRE ATT&CK

DarkComet in ATT&CK

52 distinct techniques

Techniques

52 techniques
T1059.003 Windows Command Shell T1112 Modify Registry T1057 Process Discovery T1105 Ingress Tool Transfer T1547.001 Registry Run Keys / Startup Folder T1071.001 Web Protocols T1033 System Owner/User Discovery T1056.001 Keylogging T1059 Command and Scripting Interpreter T1219 Remote Access Tools T1082 System Information Discovery T1036 Masquerading T1566 Phishing T1071 Application Layer Protocol T1053.005 Scheduled Task T1574.001 DLL T1555 Credentials from Password Stores T1539 Steal Web Session Cookie T1204.002 Malicious File T1204 User Execution T1546 Event Triggered Execution T1583 Acquire Infrastructure T1560 Archive Collected Data T1649 Steal or Forge Authentication Certificates T1083 File and Directory Discovery T1529 System Shutdown/Reboot T1059.007 JavaScript T1219.001 IDE Tunneling T1010 Application Window Discovery T1123 Audio Capture T1048 Exfiltration Over Alternative Protocol T1059.005 Visual Basic T1090.001 Internal Proxy T1115 Clipboard Data T1125 Video Capture T1543.003 Windows Service T1203 Exploitation for Client Execution T1189 Drive-by Compromise T1566.001 Spearphishing Attachment T1036.005 Match Legitimate Resource Name or Location T1562 Impair Defenses T1027 Obfuscated Files or Information T1657 Financial Theft T1113 Screen Capture T1005 Data from Local System T1562.001 Disable or Modify Tools T1562.004 Disable or Modify System Firewall T1027.002 Software Packing T1021.001 Remote Desktop Protocol T1573 Encrypted Channel T1055 Process Injection T1055.001 Dynamic-link Library Injection

Reporting

Research mentioning DarkComet

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybitโ€™s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APTโ€™s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Sep 12
Mitre Attack Website

Boot or Logon Autostart Execution, Technique T1547 - Enterprise | MITRE ATT&CKยฎ

Aug 18
Cyble Blog Historic

Cyble - BianLian: New Ransomware Variant On The Rise

BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.

Sep 2
Eset Welivesecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.