ATT&CKReferencesTrendMicro DarkComet Sept 2014

TrendMicro DarkComet Sept 2014

TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareDarkComet

DarkComet gathers the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareDarkComet

DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.

T1056.001
Keylogging
MalwareDarkComet

DarkComet has a keylogging capability.

T1082
System Information Discovery
MalwareDarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareDarkComet

DarkComet can load any files onto the infected machine to execute.

T1112
Modify Registry
MalwareDarkComet

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1123
Audio Capture
MalwareDarkComet

DarkComet can listen in to victims' conversations through the system’s microphone.

T1125
Video Capture
MalwareDarkComet

DarkComet can access the victim’s webcam to take pictures.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1685
Disable or Modify Tools
MalwareDarkComet

DarkComet can disable Security Center functions like anti-virus.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.