EXECUTIVE SUMMARY:
DarkComet is a stealthy Remote Access Trojan (RAT) used by attackers to gain unauthorized access and control over compromised systems. Originally developed as a legitimate tool, it has been widely adopted by threat actors due to its user-friendly interface and extensive feature set. Malware enables attackers to steal sensitive information, execute commands remotely, and maintain persistence, often evading detection by disabling antivirus programs and exploiting system vulnerabilities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
DarkComet is a stealthy Remote Access Trojan (RAT) used by attackers to gain unauthorized access and control over compromised systems. Originally developed as a legitimate tool, it has been widely adopted by threat actors due to its user-friendly interface and extensive feature set. Malware enables attackers to steal sensitive information, execute commands remotely, and maintain persistence, often evading detection by disabling antivirus programs and exploiting system vulnerabilities.[emaillocker id="1283"]
DarkComet operates by altering file attributes to avoid detection, such as hiding its executable or marking it as a system file. It can modify process privileges to escalate its access rights, ensuring that it maintains control over the infected machine. The malware communicates with a specified Command and Control (C2) server to exfiltrate data and receive further instructions. Additionally, it gathers system information, including hardware profiles and location settings, while also capturing keystrokes and manipulating the display. DarkComet uses advanced persistence techniques by modifying Windows registry keys and ensuring that only one instance of the malware runs at a time.
DarkComet remains a potent and adaptable RAT that continues to pose a significant threat to both individual users and organizations. Its ability to stealthily infect systems, maintain persistence, and facilitate remote control and data exfiltration makes it a valuable tool for attackers. This analysis highlights malware’s extensive capabilities, including system manipulation, data theft, and remote execution of commands. Organizations must employ strong measures to detect and mitigate the impact of DarkComet infections.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1112 | Modify Registry |
| T1564 | Hide Artifacts | |
| Discovery | T1012 | Query Registry |
| T1082 | System Information Discovery | |
| T1614 | System Location Discovery | |
| Command and Control | T1102 | Web Service |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/darkcomet-rat/