Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 8 actorsExploits 5 CVEs

DarkComet

Also known asDarkKometFYNLOSFynloskiKrademok

DarkComet is a Win32 remote access trojan/backdoor for Windows NT-based systems, also referred to in the provided content as DarkKomet, Darkkomet, Fynlos, Fynloski, and Krademok. It is designed to remotely control or administer an infected computer, with encrypted connection parameters embedded in the executable. Documented capabilities in the provided content include collecting host information such as the username, controlling processes, interpreting remote commands, listing windows, providing remote desktop access, managing services, modifying the Windows registry, deleting programs, modifying files through a built-in file manager, downloading/sending/executing files, executing remotely supplied JavaScript and VBScript, capturing webcam images and audio/video from webcam or microphone, stealing clipboard contents, acting as a SOCKS proxy, redirecting IP addresses and ports, shutting down or restarting the OS, and logging keystrokes locally in %APPDATA%dclogs using YY-MM-DD.dc filenames, with the ability to send logs to a remote FTP server. The content also notes DarkComet can disable Security Center or antivirus-related functions. In recent reporting cited in the content, DarkComet-family payloads were distributed via malicious Steam Workshop Wallpaper Engine application wallpapers since late 2025, including a sample that dropped a DarkKomet backdoor as Synaptics.exe, alongside a tampered AggregatorHost.dll that searched for Steam, hijacked active Steam sessions, and exfiltrated stolen data to attacker-controlled infrastructure including 120.48.156.17/ey.php; this campaign primarily affected gamers, especially in China and Russia, and also delivered Lumma, Vidar, cryptominers, loaders, and ransomware. The content also associates DarkComet with spearphishing operations by the ModifiedElephant threat actor targeting human rights activists, defenders, academics, journalists, and lawyers in India, where malicious documents delivered DarkComet and NetWire. Additional reporting in the content links DarkComet to Transparent Tribe-related lures targeting Indian diplomatic and military personnel. High-confidence indicators directly tied in the content to DarkComet-related Wallpaper Engine activity include the dropped filename Synaptics.exe, the path C:\ProgramData\Synaptics, the auxiliary file ._cache_GAME1.exe, the malicious library AggregatorHost.dll, the URL hxxp://120.48.156[.]17/ey.php, and the detection name HEUR:Backdoor.Win32.DarkKomet.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

5 CVES
CVE-2015-1641Microsoft Office RTF Memory Corruption RCEExploited in the wild

Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

via sentinelone labssentinelone.com
CVE-2012-0158MSCOMCTL.OCX ActiveX Controls Remote Code ExecutionExploited in the wild

Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

via sentinelone labssentinelone.com
CVE-2013-3906Remote Code Execution in Microsoft GDI+ TIFF ParsingExploited in the wild

Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

via sentinelone labssentinelone.com
CVE-2014-1761Remote Code Execution in Microsoft Word via Crafted RTF DataExploited in the wild

Observed lure documents repeatedly made use of CVE-2012-0158, CVE-2014-1761, CVE-2013-3906, CVE-2015-1641 exploits to drop and execute their malware of choice. | The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

via sentinelone labssentinelone.com
CVE-2010-3333RTF Stack Buffer Overflow in Microsoft OfficeExploited in the wild

"...spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158..." | "...off-the-shelf remote administration tools (RATs) and downloaders, such as DarkComet and Bozok."

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
THREAT ACTORS

Groups observed using it

8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Transparent Tribe

Payload (older): 07e44ffcffde46ad96eb9c018bed6193 (DarkComet)

via proofpointproofpoint.com
ModifiedElephant

The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers... The primary malware families deployed were NetWire and DarkComet remote access trojans (RATs).

via sentinelone labssentinelone.com
SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

via bleeping computerbleepingcomputer.com
Molerats

google.wwwhost.biz also hosted two DarkComet samples, which communicated with r.ddns.me , which shared IP address 198.105.125.158 with a.ddns.me , which shared IP address 23.229.3.37 with MOLERATS domain test.cable-modem.org .

via citizenlabcitizenlab.ca
APT33

DarkComet (Backdoor.Breut): Another commodity RAT used to open a backdoor on an infected computer and steal information.

via symantec enterprise blogssymantec-enterprise-blogs.security.com
APT38

Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"

via wikipedia cyber incidentsen.wikipedia.org
MITRE ATT&CK

Techniques & procedures

30 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence1

Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages... specifically through the Wallpaper Engine application, to distribute malware.

Execution

6 techniques
T1059Command and Scripting InterpreterEvidence5

Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs.

T1059.005Visual BasicEvidence1

The program performs the following functions: Running JavaScript / VBScript scripts sent remotely.

T1059.007JavaScriptEvidence1

The program performs the following functions: Running JavaScript / VBScript scripts sent remotely.

T1204User ExecutionEvidence4

Researchers discovered dozens of malicious wallpapers on Steam Workshop that abused Wallpaper Engine's Application Wallpaper feature to execute malware on users' PCs.

T1204.002Malicious FileEvidence7

The app supports four wallpaper types, and one of them, the "application wallpaper," is a standalone executable Windows program that runs as the desktop background. That also makes it a pathway for third-party code to execute on a user's machine, which is exactly what attackers exploited.

T1574.001DLLEvidence2

In a sample examined last December, the researchers managed to boot a functional desktop game while discreetly dropping a DarkKomet backdoor named Synaptics.exe and a tampered system library, AggregatorHost.dll.

Persistence

3 techniques
T1112Modify RegistryEvidence1

The program performs the following functions: ... Modifying the system registry.

T1543.003Windows ServiceEvidence1

The program performs the following functions: ... Managing system services.

T1546Event Triggered ExecutionEvidence1

These malicious wallpapers... can lead to... system compromise with backdoors... with examples including the DarkKomet backdoor...

Privilege Escalation

2 techniques
T1543.003Windows ServiceEvidence1

The program performs the following functions: ... Managing system services.

T1546Event Triggered ExecutionEvidence1

These malicious wallpapers... can lead to... system compromise with backdoors... with examples including the DarkKomet backdoor...

Stealth

2 techniques
T1036MasqueradingEvidence2

Эксперты пишут, что один из обнаруженных образцов малвари маскировался под игровые обои. После запуска пользователь видел полностью рабочую игру и не замечал ничего подозрительного.

T1574.001DLLEvidence2

In a sample examined last December, the researchers managed to boot a functional desktop game while discreetly dropping a DarkKomet backdoor named Synaptics.exe and a tampered system library, AggregatorHost.dll.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

The program performs the following functions: ... Modifying the system registry.

Credential Access

4 techniques
T1056.001KeyloggingEvidence1

The program performs the following functions: Saving keystrokes to a file ... Sending keystroke logs to a remote FTP server.

T1539Steal Web Session CookieEvidence1

That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server.

T1555Credentials from Password StoresEvidence1

That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server.

T1649Steal or Forge Authentication CertificatesEvidence1

A custom version of a system library called 'AggregatorHost.dll' was also installed to search for Steam accounts on the computer and steal account credentials.

Discovery

4 techniques
T1010Application Window DiscoveryEvidence1

The program performs the following functions: Obtaining a list of windows.

T1057Process DiscoveryEvidence1

The program performs the following functions: ... Controlling processes.

T1082System Information DiscoveryEvidence1

The program performs the following functions: Obtaining information about the infected computer.

T1083File and Directory DiscoveryEvidence1

The program performs the following functions: Modifying files via the built-in file manager.

Collection

5 techniques
T1056.001KeyloggingEvidence1

The program performs the following functions: Saving keystrokes to a file ... Sending keystroke logs to a remote FTP server.

T1115Clipboard DataEvidence1

The program performs the following functions: Capturing clipboard contents.

T1123Audio CaptureEvidence1

The program performs the following functions: Capturing video and audio from a webcam or microphone.

T1125Video CaptureEvidence1

The program performs the following functions: Capturing video and audio from a webcam or microphone.

T1560Archive Collected DataEvidence1

Analysis of compromised wallpapers revealed that the malware is bundled either directly in the package or inside password-protected archives that the user is tricked into opening.

Command and Control

5 techniques
T1071Application Layer ProtocolEvidence2

That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server.

T1090.001Internal ProxyEvidence1

The program performs the following functions: Acting as a SOCKS proxy server.

T1105Ingress Tool TransferEvidence4

Indicators of Compromise (IOC) List Domain/URL: http://202.144.192.29/download2/Themes2.zip ... http://brightly.to/download2/Themes2.zip ... https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1 ... https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download

T1219Remote Access ToolsEvidence2

The wallpaper drops Synaptics.exe, a backdoor belonging to the DarkKomet remote access trojan family, into C:\ProgramData\Synaptics\ .

T1219.001IDE TunnelingEvidence1

The program performs the following functions: ... Providing remote desktop access.

Exfiltration

1 technique
T1048Exfiltration Over Alternative ProtocolEvidence1

The program performs the following functions: Sending keystroke logs to a remote FTP server.

Impact

1 technique
T1529System Shutdown/RebootEvidence1

The program performs the following functions: Shutting off and restarting the operating system.

INDICATORS OF COMPROMISE

IOCs tracked for this family

61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
14 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
19 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
28 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app11 days ago
uri●●●●●●●●●●●●View more in app11 days ago
hash.md5●●●●●●●●●●●●View more in app11 days ago
hash.md5●●●●●●●●●●●●View more in app11 days ago
ip.v4●●●●●●●●●●●●View more in app11 days ago
uri●●●●●●●●●●●●View more in app11 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching61

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution8

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities5

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping30

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.