Cyber Threat Report: 'Detailed Analysis of DarkGate'

Report Author S2W
Publication Date 2024-01-16
Original Reporting Source
Related Intrusion Sets DarkGate Operators (RastaFarEye)
Identified CVEs CVE-2021-1733

This post on Medium by S2W presents a technical analysis of DarkGate malware and the operator behind it. According to the report, DarkGate is a backdoor malware developed since 2017 and sold as Malware-as-a-Service, gaining popularity in 2021 with continuous feature updates and detection bypasses. It enables remote code execution, data exfiltration, cryptocurrency mining, privilege escalation, and persistence management. The post states that DarkGate is mainly distributed via VBScript or MSI, using techniques like DLL Side-loading and AutoIT scripts for execution.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques