EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/darkcomet-rat-2012
340/430

File EL-0091HighResolvedCyberattack / Remote Access Trojan (RAT)

DarkComet RAT

Also filed as DarkComet Remote Access Trojan · DarkComet Backdoor

DarkComet was a Remote Access Trojan (RAT) widely distributed around 2012, primarily targeting Windows operating systems. It allowed attackers to gain unauthorized remote control over infected machines. The malware was known for its ability to steal credentials, capture keystrokes, and exfiltrate sensitive data.

  • #rat
  • #backdoor
  • #malware
  • #cybercrime
  • #windows
Notoriety6/10
Event
1 Jan 2012
Disclosed
1 Jan 2012
Target
General Windows Users
Status
Resolved

01Summary

DarkComet operated as a sophisticated backdoor, granting attackers persistent, covert access to victim systems. Its primary function was espionage and financial theft, allowing remote execution of commands and the interception of communications. Infection typically occurred through malicious downloads or compromised websites, exploiting user trust in seemingly legitimate software. Once installed, the RAT established a persistent connection, making the victim's machine a beachhead for further attacks. The malware's capabilities included screen capture, microphone activation, and the theft of stored passwords, making it a significant threat to both individuals and small businesses.

02Background

The early 2010s saw a proliferation of commodity malware designed for mass exploitation. DarkComet fit this profile, representing a common threat vector for cybercriminals seeking quick, high-volume returns. Its existence highlighted the growing vulnerability of personal and corporate networks to easily deployable, yet highly effective, remote access tools.

03Key revelations

  1. 01The ability to remotely activate the microphone and camera.
  2. 02The capability to capture keystrokes in real-time (keylogging).
  3. 03The use of encrypted channels to evade network monitoring.

04Technical analysis

DarkComet utilized standard Windows APIs for its operations, making it difficult to detect without behavioral analysis. It often communicated over common ports (like HTTP/S) to blend in with normal network traffic. The malware was designed to be modular, allowing attackers to add specific functionalities (e.g., keylogging, file transfer) as needed.

Attack vector
Malicious downloads, compromised websites, and phishing campaigns.
Attack method
Remote Access Trojan (RAT) deployment and command-and-control (C2) communication.
Initial access
User execution of malicious payload.
Lateral movement
Remote command execution via C2 channel.
Persistence
Registry modification and scheduled tasks.
Exfiltration
Encrypted outbound network connections (HTTP/S).
Tool / malware
DarkComet
Malware family
RAT
Malware type
Spyware/Backdoor

Vulnerabilities exploited

  • General OS Vulnerabilities (User Exploitation)

MITRE ATT&CK techniques

  • T1021.001
  • T1053

05Threat actor

The perpetrators were likely financially motivated criminal groups operating for profit. They specialized in creating and distributing commodity malware, selling access or data to the highest bidder on underground forums.

Aliases

  • Unknown Threat Actor

MITRE groups

  • T1021.001
  • T1053

Attribution sources

  • Security Vendors

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Keystrokes
  • Personal Identifiable Information (PII)
  • Screen Captures

Notable documents

  • C2 Command Logs
  • Stolen Credentials Dump

08Financial damage

Damage was primarily due to identity theft and corporate espionage, making precise quantification difficult.

09Timeline

  1. 2011-12-01Initial observed activity and distribution of the DarkComet payload.
  2. 2012-01-01Malware publicly discovered and analyzed by security researchers.
  3. 2012-06-01Threat activity significantly reduced and deemed largely contained.

10Reaction and fallout

Public reaction

The discovery of DarkComet raised public awareness regarding the necessity of robust endpoint security and user vigilance against suspicious downloads. It contributed to the increased focus on behavioral detection methods in cybersecurity.

Political impact

The incident reinforced the need for stronger international cooperation in cybercrime enforcement, particularly concerning the rapid deployment of commodity malware.

11Legal

No specific high-profile legal action was directly attributed to DarkComet, but it contributed to the general tightening of cybercrime laws globally.

12Aftermath

Policy changes

  • Increased emphasis on endpoint detection and response (EDR) solutions.

Security improvements

  • Mandatory multi-factor authentication (MFA) implementation.
  • Improved network segmentation to limit lateral movement.

13Significance and legacy

Significance

DarkComet represents a classic example of a high-volume, low-effort cybercrime tool. Its widespread use demonstrated the maturity of the cybercriminal market, where sophisticated functionality was packaged into easily deployable, commodity malware for maximum profit.

Legacy

The threat model established by DarkComet—remote access via simple payloads—remains relevant. It spurred the development of advanced anti-malware techniques focusing on behavioral analysis rather than just signature matching.

14Disclosure and media

Authentication
Reverse Engineering Analysis

Publishing organisations

  • Security Research Firms

15Field notes

  1. 01The RAT was often bundled with other, less malicious software to increase its perceived legitimacy.
  2. 02Its modular design allowed it to adapt to different target environments without requiring a full code rewrite.

16Resolution

The threat was mitigated through updated antivirus signatures, behavioral detection rules, and public awareness campaigns.

17Sources

References

  1. [1]Security Vendor Threat Reports (2012)
Fact sheetEL-0091

Dates

Event
1 Jan 2012
Started
1 Dec 2011
Ended
1 Jun 2012
Duration
151 days
Discovered
1 Jan 2012
Disclosed
1 Jan 2012
Resolved
1 Jun 2012
Ongoing
No

Target

Organisation
General Windows Users
Type
Individual
Sector
General Computing
Country
Global

Actor

Type
Criminal Gang
Motivation
Financial gain through unauthorized remote access and data theft.
Arrested
No
Convicted
No

Data

Sensitivity
Confidential
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.