Darktrack received some publicity in late 2016 for being a free Remote Access Trojan (RAT) that was comparable to some of the top commercially available RATs. Darktrack has the ability to access a victim's webcam, microphone, files, and passwords. It can also execute commands on infected machines, and make infected computers participate in DDoS attacks.
Following this publicity, the creator of the malware shut down the website, citing concerns that the tool was being used as malware or for illegal activities.
Fast-forward to May 2017, Darktrack version 5.0 was used in a targeted spearphishing attack on the Ukrainian military. Like many spearphishing attacks, the malware pretends to be a Microsoft Word document. However, once opened, it would inject the malware into the svchost.exe process on the victim's computer and display a decoy document to distract the user.