Darkkomet

Category: rat · Aliases: darkcomet, fynloski · Sample count (EMBER 2018): 801 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

DarkKomet, also known as DarkComet, is a well-known remote access trojan originally developed as legitimate remote-administration software but widely repurposed for malicious surveillance and credential theft. Notable for its use in surveillance campaigns against journalists and activists in the early 2010s, DarkComet provides keylogging, webcam capture, file transfer, and remote shell. Its development was officially discontinued in 2012, but the publicly-available builders remain in widespread use.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1056.001 T1547.001 T1125

Frequently Asked Questions

What is Darkkomet?

DarkKomet, also known as DarkComet, is a well-known remote access trojan originally developed as legitimate remote-administration software but widely repurposed for malicious surveillance and credential theft. Notable for its use in surveillance campaigns against journalists and activists in the early 2010s, DarkComet provides keylogging, webcam capture, file transfer, and remote shell. Its development was officially discontinued in 2012, but the publicly-available builders remain in widespread use.

How does Darkkomet spread?

DarkKomet (DarkComet) is distributed through cracked-software bundles, malicious email attachments, and underground RAT marketplaces despite its original developer ceasing distribution in 2012.

What are the signs of a Darkkomet infection?

Webcam or keystroke logging indicators, hidden processes, persistence via Run registry keys, and antivirus alerts for DarkComet or Fynloski are common signs.

What should I do if I think I have Darkkomet on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/darkkomet.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.