DarkComet — Malware Profile
DarkComet is a Windows remote administration tool and backdoor.
MITRE ATT&CK techniques (18)
- T1021.001 Remote Desktop Protocol
- T1027.002 Software Packing
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.003 Windows Command Shell
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1115 Clipboard Data
- T1123 Audio Capture
- T1125 Video Capture
- T1547.001 Registry Run Keys / Startup Folder
- T1685 Disable or Modify Tools
- T1686.003 Windows Host Firewall
IntelFusions coverage
- APT33: Iran's IRGC-Linked Espionage Group Targets Aviation, Energy, and Defense Across Three Continents 2026-02-16
- Malicious Steam wallpapers hijack gamers' accounts and drop backdoors 2026-06-16
Attributed threat actors
- SilverTerrier
- Operation C-Major machine-inferred link
- Transparent Tribe
- APT38
- APT33 machine-inferred link