Skip to content

DarkComet

DarkComet is a Windows remote access trojan and backdoor used to remotely control compromised systems.

Profile source: Mallory opens in a new tab

DarkComet

Family profile

DarkComet is a Windows remote access trojan and backdoor used to remotely control compromised systems. It is a long-established commodity RAT associated with surveillance, credential and data theft, and general post-compromise system administration by attackers. The malware supports remote command execution and broad host control functions, including process and service management, file transfer and file manipulation, registry modification, remote desktop access, script execution, system reboot or shutdown, and proxying capabilities. Documented collection features include keylogging, clipboard theft, webcam capture, host user discovery, and exfiltration of stolen data such as keystroke logs.

DarkComet has been observed in both opportunistic and targeted intrusion activity. It has been used by threat actors in spearphishing campaigns with malicious documents, including operations attributed to ModifiedElephant and activity associated with Transparent Tribe reporting. It has also appeared in more recent malware distribution campaigns abusing Steam Workshop and Wallpaper Engine application wallpapers, where weaponized wallpaper packages silently installed a DarkComet-family backdoor while presenting benign-looking content to the victim. In those campaigns, DarkComet was one of several payloads delivered to gamers, alongside infostealers, loaders, cryptominers, and ransomware, with Steam account theft and session abuse as prominent objectives.

DarkComet targets Windows systems and is commonly characterized as a RAT/backdoor family rather than a specialized stealer. Its functionality makes it suitable for persistent access, surveillance, and follow-on payload delivery, and it remains a recognizable malware family in incident response despite its age.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 6, 2026
Feed role
C2
Host form
2 IP / 3 hostnames

Leading locations

  • BR1
  • FR1
  • TR1
  • UA1

Leading providers

  • Datema Bilisim Ticaret Anonim Sirketi1
  • Oracle Corporation1
  • V tal1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
ModifiedElephant

The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

Molerats

google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .

APT33

DarkComet (Backdoor.Breut): Another commodity RAT used to open a backdoor on an infected computer and steal information.

BlueNoroff

Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"

Aluminum Saratoga

“ALUMINUM SARATOGA uses many openly available tools for its operations, including… DarkComet…”

Exploited software

Vulnerabilities linked to DarkComet

5 CVEs

MITRE ATT&CK

DarkComet in ATT&CK

50 distinct techniques

Techniques

50 techniques

Reporting

Research mentioning DarkComet

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Sep 12
Mitre Attack Website

Boot or Logon Autostart Execution, Technique T1547 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.