Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 17 hostnames
DarkComet is a Windows remote access trojan that provides an operator with broad control over an infected system.
Profile source: Mallory opens in a new tabDarkComet
DarkComet is a Windows remote access trojan that provides an operator with broad control over an infected system. It is widely known as a commodity RAT and has been used both by criminal operators and in targeted intrusions. Reported capabilities include remote administration, process enumeration, script execution, keylogging, collection of victim username information, file transfer, and persistence through Windows autostart mechanisms. It has also been observed using masquerading tactics by adopting names resembling legitimate Windows or security-related software.
DarkComet commonly establishes persistence by creating Registry-based autorun entries and has also been associated with Startup-folder persistence. Observed behavior includes modification of Windows Registry values, including changes intended to support execution at logon or startup and, in some cases, weaken security settings. It can enumerate active processes on the host and gather basic host and user context for operator awareness.
The malware has been linked in public reporting to multiple threat actors and intrusion sets, including use by APT33 and references alongside Lazarus-related tooling, though DarkComet itself is broadly available and not exclusive to any single actor. It has also appeared in malware repositories and has been delivered by other malware families and downloaders. Public reporting further notes use of cloud tunneling services such as ngrok to conceal command-and-control infrastructure. DarkComet has been observed in phishing-related ecosystems and in targeted attack reporting affecting government and regional victims, particularly within older Windows-centric intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
51c45fb238881bd25fd7435d8b8e44eee9cc56887a56a7e5f5bdef8ec8392465 3388ad9c396144b5c1fda8b3bbfbb1367e0e193072333fe7784285d6d43351a1 62781ea348ad4c476fb1f2ea8307452035e8db241171baeadf0c6ae221cfb5d4 bbd4037a77ba5fb6b9e0322be02bf0b400639197265d0a8f7f53b72a1c8d17e1 f9a15a20aba0509bd19723576b41d0e3661544ef1d69a6d7004bbb5dc52a9d6d 06f4f7315c6503acc354e0adfa4fdaceef1db98eb9aeb76e426a79992e0e7009 ac7f5064bdccc00df1e3896184526a159dc58c459518459d573ae460f4daf485 3f0b1837b836c8f882db35bc5b0510b47e6c06a996148371a05b2d2b8b46ee0f 9e31b4fadf95a81fc425f01332853640931d69c5a54202747716952cb067d052 4f1cc412ba0d8a92cfb4d78431b2c81dc50001ca5c5405ce8c8f0ec0496b8ec8 Reported operators
APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
Payload (older): 07e44ffcffde46ad96eb9c018bed6193 (DarkComet)
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
File-based ... Trojan.Darkcomp ...
Exploited software
MITRE ATT&CK
Reporting
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybitโs affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APTโs leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.
ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.