Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 15:17:39 UTC Home > List all groups > List all tools > List all groups using tool DarkComet Tool: DarkComet Names DarkComet DarkKomet Fynloski FYNLOS klovbot Krademok Breut Category Tools Type Backdoor, Keylogger, Credential stealer, Info stealer Description (Wikipedia) DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur (known as DarkCoderSc), an independent programmer and computer security coder from France. Although the RAT was developed back in 2008, it began to proliferate at the start of 2012. The program was discontinued, partially due to its use in the Syrian civil war to monitor activists but also due to its author's fear of being arrested for unnamed reasons. As of August 2018, the program's development 'has ceased indefinitely', and downloads are no longer offered on its official website. DarkComet allows a user to control the system with a graphical user interface. It has many features which allows a user to use it as administrative remote help tool; however, DarkComet has many features which can be used maliciously. DarkComet is commonly used to spy on the victims by taking screen captures, key-logging, or password stealing. Information MITRE ATT&CK https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=750a87d7-5356-4e78-84ec-d49dc4f3241d Page 1 of 2 Malpedia AlienVault OTX Last change to this tool card: 28 December 2022 Download this tool card in JSON format All groups using tool DarkComet Changed Name Country Observed APT groups   APT 33, Elfin, Magnallium 2013-Apr 2024     Lazarus Group, Hidden Cobra, Labyrinth Chollima 2007-May 2025   Transparent Tribe, APT 36 2013-Mar 2025   3 groups listed (3 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=750a87d7-5356-4e78-84ec-d49dc4f3241d https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=750a87d7-5356-4e78-84ec-d49dc4f3241d Page 2 of 2