DarkGate

MITRE ATT&CK: S1111 View on attack.mitre.org

Aliases: Meh, MehCrypter, DarkGate

First seen
2018-01-01 00:00:00
Malware type
credential-stealer, cryptominer, trojan, ransomware
Family
Malware family
Operating systems
windows
Related IoCs
2489 (2032 malicious)
Last IoC activity
2026-09-02 02:42:41
Profile updated
2026-07-07 13:12:25

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical

Context

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.

Recent IoC activity

2,027 malicious indicators in Maltiverse are attributed to DarkGate (S1111). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname whoernet.co.com 2026-09-03 2
hostname tfciltd.com 2026-09-03 2
hostname wilenters.com 2026-09-03 1
hostname arishhomeschool.com.ng 2026-09-03 3
hostname higreens.co.in 2026-09-03 2
hostname silkylearning.com 2026-09-03 2
hostname pjnbadfjandkadm3kd.com 2026-09-03 1
hostname computersupportexperts.com 2026-09-03 2
hostname vivekwp.com 2026-09-03 2
hostname mycopier.com.my 2026-09-03 4
hostname megalista.com.br 2026-09-03 2
hostname innomecanica.cl 2026-09-03 2
hostname nativesfilmworks.com 2026-09-03 2
hostname clubhousefinancialgroup.com 2026-09-03 2
hostname certucheabogados.com 2026-09-03 2
hostname hmas.mx 2026-09-02 3
hostname dma24.com 2026-09-02 2
hostname autumnagedcare.com.au 2026-09-02 4
hostname rocksecuritymw.com 2026-09-02 2
hostname freedomsepter.com 2026-09-02 1

Detection coverage

  • 4 YARA rules
  • 996 Sigma rules

Malware & tools used

  • Service Execution (attack-pattern)
  • DNS (attack-pattern)
  • Automated Collection (attack-pattern)
  • Hijack Execution Flow (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Double File Extension (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Unsecured Credentials (attack-pattern)
  • Data from Local System (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Rename Legitimate Utilities (attack-pattern)
  • PowerShell (attack-pattern)

Used by threat actors

  • Emmenhtal Loader Distribution Activity (campaign)
  • Water Curupira Pikabot Distribution (campaign)
  • Windows SmartScreen Bypass (CVE-2024-21412) DarkGate Campaign (campaign)

Exploited vulnerabilities

  • CVE-2024-21412 (vulnerability)

Detection rules

  • RUSSIANPANDA_Darkgate_Autoit (yara-rule)
  • EMBEERESEARCH_Win_Darkgate_Xllloader_Oct_2023 (yara-rule)
  • CAPE_Darkgateloader (yara-rule)
  • CAPE_Darkgate (yara-rule)

Reports & references

  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • proofpoint.com — Clipboard Compromise Powershell Self Pwn (report)
  • cloud.google.com — Detecting Disrupting Malvertising Backdoors (report)
  • Kaspersky — 110286 (report)
  • securityintelligence.com — Spam Trends Campaigns Senior Superlatives 2023 (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • orangecyberdefense.com — Cybersoc Insights Analyse Einer Black Basta Angriffskampagne (report)
  • rapid7.com — Black Basta Ransomware Campaign Drops Zbot Darkgate And Custom Malware (report)
  • x.com — 1736758775326146778 (report)
  • Mandiant — Detecting Disrupting Malvertising Backdoors (report)
  • esentire.com — From Darkgate To Danabot (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Darkgate (report)
  • github.com — Extractor.Py (report)
  • embee-research.ghost.io — Practical Signatures For Identifying Malware With Yara (report)
  • github.com — Darkgate.Md (report)
  • blog.sekoia.io — Darkgate Internals (report)
  • github.security.telekom.com — Darkgate Loader (report)
  • proofpoint.com — Battleroyal Darkgate Cluster Spreads Email And Fake Browser Updates (report)
  • splunk.com — Enter The Gates An Analysis Of The Darkgate Autoit Loader (report)
  • Trend Micro — Darkgate Opens Organizations For Attack Via Skype Teams (report)
  • truesec.com — Darkgate Loader Delivered Via Teams (report)
  • medium.com — Shortandmalicious Darkgate D9102A457232 (report)
  • cybersecurity.att.com — Darkgate Malware Delivered Via Microsoft Teams Detection And Response (report)
  • kroll.com — Brute Forcing Darkgate Encodings (report)
  • trellix.com — The Continued Evolution Of The Darkgate Malware As A Service (report)

External references