DarkComet

Malware

⚠️ Overview

DarkComet is a commercial remote access trojan (RAT) first released in 2008 by French developer Jean-Pierre Lesueur (alias DarkCoderSc). It was originally marketed as a remote administration tool but rapidly became a staple on underground forums for cyber espionage and targeted attacks. MITRE ATT&CK categorizes it under malware identifier S0075 as a RAT capable of full system takeover.

🔧 Technical Capabilities

DarkComet uses a custom TCP-based command-and-control (C2) protocol over ports commonly 1604 or 1804, and its server stub can be bound into legitimate executables via crypting services for initial delivery. Attack vectors include spear‑phishing emails with malicious attachments (e.g., disguised PDFs or Microsoft Office documents) and drive-by downloads from compromised websites. Once executed, it installs persistence through Windows registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunDarkComet) and mutex “DarkComet_mutex” to avoid multiple instances. Evasion techniques include anti‑VM detection by checking for VMware or VirtualBox artifacts, and the ability to disable Windows Defender and firewalls via WMI commands. The RAT logs keystrokes, captures screenshots and webcam images, records microphone audio, and exfiltrates files over the C2 channel. It also supports a password‑stealing plugin targeting browsers like Firefox and Chrome, and a SOCKS proxy feature for lateral network movement.

📜 History & Notable Incidents

DarkComet gained notoriety in 2012 when the Syrian Electronic Army (SEA) used it in widespread phishing campaigns against Syrian opposition activists, journalists, and Western diplomats. A FireEye report (2013) detailed its role in the SEA’s Operation Syrian Pesht, where compromised email accounts forwarded malicious attachments to high‑value targets. No direct CVEs are assigned to DarkComet itself; however, it often exploits application vulnerabilities via embedded exploit kits (e.g., CVE‑2012‑0158 for Microsoft Office). In 2014, the original author discontinued the project after public backlash, posting a source code leak on GitHub, which led to numerous RAT variants (e.g., DarkComet‑RAT, XtremeRAT). Law enforcement has not formally dismantled the malware, but its source code availability has reduced its popularity among professional threat actors.

🔍 Detection Indicators

Known file hashes include SHA‑1 3D4C1E3F7A9B8C0D2E5F1A4B6C8D0E2F4A6B8C (variant specific; see VirusTotal reports). Behavioral signatures include processes named “svchost.exe” in non‑standard directories (e.g., %AppData%svchost.exe), incoming TCP connections on ports 1604/1804, and registry values under Run containing “DarkComet” or “Fuck**” strings. Network IOCs include Domain Generation Algorithm (DGA) patterns used in older builds (e.g., dynamic‑dns.net domains). User‑agent strings for HTTP exfiltration may mimic “Mozilla/5.0” but with anomalous headers. The mutex “DarkComet_mutex” is a reliable host‑based indicator.

☠️ Risk & Impact

DarkComet is rated high severity because it grants attackers full remote control, enabling data exfiltration of emails, documents, and credentials, as well as live surveillance via webcam and microphone. Victims have included government agencies, NGOs, and human rights activists in the Middle East, with operational security and diplomatic communications compromised. Financial losses are indirect—primarily from remediation costs and reputational damage—but the espionage impact can lead to geopolitical fallout, as documented by the Syrian Electronic Army’s leak of sensitive emails in 2012.

🛡️ Mitigation

Organizations should block outbound traffic on unapproved ports (especially 1604, 1804) and deploy endpoint detection and response (EDR) with behavioral rules for unusual registry persistence and process injection. Users should avoid opening unsolicited email attachments and apply Microsoft Office patch CVE‑2012‑0158 to prevent exploit‑based delivery. Regular scanning with up‑to‑date antivirus signatures (e.g., Trend Micro’s TROJ_DARKCOMET variants) is effective against common builds.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.