216.73.217.22

DarkComet RAT: Technical Analysis of Attack Chain

· Published 23/10/2024 17:36 · Modified 23/10/2024 19:49

Export JSON

Essential information

Published
23/10/2024 17:36
Modified
23/10/2024 19:49
Tags
2024-10-23 command and control darkcomet evasion keylogging persistence privilege-escalation rat remote access trojan
Related entities
1 observables, 10 techniques (mitre), 5 malware

Description

This analysis examines the () , detailing its capabilities, distribution methods, and technical operations. The malware alters file attributes, establishes communication with malicious domains, modifies process privileges, and gathers system information. It employs various mechanisms, including registry modifications. 's functionalities include simulating user input, capturing keystrokes, and manipulating system settings. The analysis reveals its ability to evade detection, escalate privileges, and execute remote commands via a (C2) server. The malware's versatility and ease of use contribute to its widespread deployment in targeted cyberattacks, making it a significant threat to cybersecurity.

External references