ATT&CKReferencesMalwarebytes DarkComet March 2018

Malwarebytes DarkComet March 2018

Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
MalwareDarkComet

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

T1027.002
Software Packing
MalwareDarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.

T1057
Process Discovery
MalwareDarkComet

DarkComet can list active processes running on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

T1059.003
Windows Command Shell
MalwareDarkComet

DarkComet can launch a remote shell to execute commands on the victim’s machine.

T1071.001
Web Protocols
MalwareDarkComet

DarkComet can use HTTP for C2 communications.

T1082
System Information Discovery
MalwareDarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareDarkComet

DarkComet can load any files onto the infected machine to execute.

T1112
Modify Registry
MalwareDarkComet

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1115
Clipboard Data
MalwareDarkComet

DarkComet can steal data from the clipboard.

T1123
Audio Capture
MalwareDarkComet

DarkComet can listen in to victims' conversations through the system’s microphone.

T1125
Video Capture
MalwareDarkComet

DarkComet can access the victim’s webcam to take pictures.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1685
Disable or Modify Tools
MalwareDarkComet

DarkComet can disable Security Center functions like anti-virus.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.