DarkComet
MITRE ATT&CK: S0334 View on attack.mitre.org
Aliases: DarkKomet, Fynloski, Krademok, FYNLOS, Breut, klovbot, DarkComet, Dark Comet
- First seen
- 2008-08-01 00:00:00
- Malware type
- backdoor, rat, keylogger
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2333 (1778 malicious)
- Last IoC activity
- 2026-09-02 02:41:20
- Profile updated
- 2026-07-07 15:45:48
Targeted industries: government-and-public-sector education-and-nonprofits financial-services technology-and-telecommunications
Context
DarkComet is a Windows remote administration tool and backdoor.
Recent IoC activity
1,782 malicious indicators in Maltiverse are attributed to DarkComet (S0334). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | savesforgames.com | 2026-09-03 | 1 |
| URL | http://savesforgames.com/wp-content/uploads/2017/files/the-chronicles-of-narn... | 2026-09-03 | 1 |
| hostname | hf1.no-ip.biz | 2026-09-03 | 1 |
| hostname | sound-educated.gl.at.ply.gg | 2026-09-03 | 1 |
| hostname | notnimdab.ddns.net | 2026-09-03 | 1 |
| hostname | mamed1.zapto.org | 2026-09-03 | 1 |
| hostname | milanilou007.ddns.me | 2026-09-03 | 1 |
| hostname | eselreiter.no-ip.biz | 2026-09-03 | 1 |
| hostname | larissa.no-ip.biz | 2026-09-03 | 1 |
| hostname | darkcomettr.no-ip.org | 2026-09-03 | 1 |
| hostname | fikohack.no-ip.biz | 2026-09-03 | 1 |
| hostname | lebkuchen.no-ip.org | 2026-09-03 | 1 |
| hostname | jtmftw.no-ip.biz | 2026-09-03 | 1 |
| hostname | darkcomet9912.no-ip.biz | 2026-09-03 | 1 |
| hostname | maxiserp.no-ip.biz | 2026-09-03 | 1 |
| hostname | j4ttb0gxg.localto.net | 2026-09-03 | 1 |
| hostname | limboland1.no-ip.biz | 2026-09-03 | 1 |
| hostname | onur11.zapto.org | 2026-09-03 | 1 |
| hostname | anonymouscheats.no-ip.org | 2026-09-03 | 1 |
| hostname | amcalar.123.duckdns.org | 2026-09-03 | 1 |
Detection coverage
- 596 Sigma rules
Malware & tools used
- Windows Host Firewall (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Clipboard Data (attack-pattern)
- Video Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Web Protocols (attack-pattern)
- Audio Capture (attack-pattern)
- Software Packing (attack-pattern)
- Modify Registry (attack-pattern)
- Keylogging (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- Transparent Tribe (threat-actor)
- APT38 (threat-actor)
- SilverTerrier (threat-actor)
Exploited vulnerabilities
- CVE-2022-47966 (vulnerability)
Reports & references
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- Mandiant — Rpt Apt38 (report)
- Mandiant — Apt Group Sends Spea (report)
- secureworks.com — Copper Fieldstone (report)
- secureworks.com — Aluminum Saratoga (report)
- sentinelone.com — Modifiedelephant Apt And A Decade Of Fabricating Evidence (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- Cisco Talos — Avoslocker New Arsenal (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- Trend Micro — How Cybercriminals Abuse Cloud Tunneling Services (report)
- contagiodump.blogspot.com — Rat Samples From Syrian Targeted (report)
- businessinsights.bitdefender.com — Tech Advisory Manageengine Cve 2022 47966 (report)
- brandefense.io — Mythic Leopard Apt Group (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Darkcomet (report)
- tgsoft.it — Download (report)
- asec.ahnlab.com — Lazarus %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Nukesped %Ec%95%85%Ec%84%B1%Ec%Bd%94%Eb%93%9C %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C (report)
- blog.malwarebytes.com — You Dirty Rat Part 1 Darkcomet (report)
- any.run — Darkcomet Rat Technical Analysis (report)
- github.com — Rat.Win.Darkcomet (report)
- sysnet.ucsd.edu — Darkmatter Www20 (report)
- sentinelone.com — Modified Elephant Apt And A Decade Of Fabricating Evidence Sentinellabs (report)
- Cisco Talos — Threat Roundup 0204 0211 (report)
- blog.malwarebytes.com — Dark Comet 2 Electric Boogaloo (report)
- MITRE ATT&CK — S0334 (report)
External references
- mitre-attack — S0334
- DarkComet
- DarkKomet
- Fynloski
- Krademok
- FYNLOS
- Malwarebytes DarkComet March 2018
- TrendMicro DarkComet Sept 2014
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy