Threat Advisory

DarkComet RAT Targeting Systems Remote to Control Stealing Sensitive Data

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

DarkComet is a stealthy Remote Access Trojan (RAT) used by attackers to gain unauthorized access and control over compromised systems. Originally developed as a legitimate tool, it has been widely adopted by threat actors due to its user-friendly interface and extensive feature set. Malware enables attackers to steal sensitive information, execute commands remotely, and maintain persistence, often evading detection by disabling antivirus programs and exploiting system vulnerabilities.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

DarkComet is a stealthy Remote Access Trojan (RAT) used by attackers to gain unauthorized access and control over compromised systems. Originally developed as a legitimate tool, it has been widely adopted by threat actors due to its user-friendly interface and extensive feature set. Malware enables attackers to steal sensitive information, execute commands remotely, and maintain persistence, often evading detection by disabling antivirus programs and exploiting system vulnerabilities.[emaillocker id="1283"]

DarkComet operates by altering file attributes to avoid detection, such as hiding its executable or marking it as a system file. It can modify process privileges to escalate its access rights, ensuring that it maintains control over the infected machine. The malware communicates with a specified Command and Control (C2) server to exfiltrate data and receive further instructions. Additionally, it gathers system information, including hardware profiles and location settings, while also capturing keystrokes and manipulating the display. DarkComet uses advanced persistence techniques by modifying Windows registry keys and ensuring that only one instance of the malware runs at a time.

DarkComet remains a potent and adaptable RAT that continues to pose a significant threat to both individual users and organizations. Its ability to stealthily infect systems, maintain persistence, and facilitate remote control and data exfiltration makes it a valuable tool for attackers. This analysis highlights malware’s extensive capabilities, including system manipulation, data theft, and remote execution of commands. Organizations must employ strong measures to detect and mitigate the impact of DarkComet infections.

 

THREAT PROFILE:

Tactic Technique Id Technique
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1112 Modify Registry
T1564 Hide Artifacts
Discovery T1012 Query Registry
T1082 System Information Discovery
T1614 System Location Discovery
Command and Control T1102 Web Service

 

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/darkcomet-rat/

[/emaillocker]
crossmenu