Malware.View on attack.mitre.org
DarkComet is a Windows remote administration tool and backdoor.
| Technique | Procedure example |
|---|---|
| T1021.001 Remote Desktop Protocol |
DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard. |
| T1027.002 Software Packing |
DarkComet has the option to compress its payload using UPX or MPRESS. |
| T1033 System Owner/User Discovery |
DarkComet gathers the username from the victim’s machine. |
| T1036.005 Match Legitimate Resource Name or Location |
DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file. |
| T1056.001 Keylogging |
DarkComet has a keylogging capability. |
| T1057 Process Discovery |
DarkComet can list active processes running on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
DarkComet can execute various types of scripts on the victim’s machine. |
| T1059.003 Windows Command Shell |
DarkComet can launch a remote shell to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
DarkComet can use HTTP for C2 communications. |
| T1082 System Information Discovery |
DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine. |
| T1105 Ingress Tool Transfer |
DarkComet can load any files onto the infected machine to execute. |
| T1112 Modify Registry |
DarkComet adds a Registry value for its installation routine to the Registry Key |
| T1115 Clipboard Data |
DarkComet can steal data from the clipboard. |
| T1123 Audio Capture |
DarkComet can listen in to victims' conversations through the system’s microphone. |
| T1125 Video Capture |
DarkComet can access the victim’s webcam to take pictures. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.