DarkComet

S0334

Malware.View on attack.mitre.org

About this malware

DarkComet is a Windows remote administration tool and backdoor.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

T1027.002
Software Packing

DarkComet has the option to compress its payload using UPX or MPRESS.

T1033
System Owner/User Discovery

DarkComet gathers the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location

DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.

T1056.001
Keylogging

DarkComet has a keylogging capability.

T1057
Process Discovery

DarkComet can list active processes running on the victim’s machine.

T1059
Command and Scripting Interpreter

DarkComet can execute various types of scripts on the victim’s machine.

T1059.003
Windows Command Shell

DarkComet can launch a remote shell to execute commands on the victim’s machine.

T1071.001
Web Protocols

DarkComet can use HTTP for C2 communications.

T1082
System Information Discovery

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1105
Ingress Tool Transfer

DarkComet can load any files onto the infected machine to execute.

T1112
Modify Registry

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1115
Clipboard Data

DarkComet can steal data from the clipboard.

T1123
Audio Capture

DarkComet can listen in to victims' conversations through the system’s microphone.

T1125
Video Capture

DarkComet can access the victim’s webcam to take pictures.

View all 18 procedure examples

Groups that use it3

Campaigns0

None recorded.

References2

  1. Malwarebytes DarkComet March 2018 Open source
    Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.
  2. TrendMicro DarkComet Sept 2014 Open source
    TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.