Skip to content

DarkGate

DarkGate is a Windows malware family most commonly characterized as a remote access trojan used in financially motivated intrusion chains.

Profile source: Mallory opens in a new tab

DarkGate

Family profile

DarkGate is a Windows malware family most commonly characterized as a remote access trojan used in financially motivated intrusion chains. It has been observed as a payload in multiple delivery ecosystems, including ClickFix-style social-engineering campaigns, phishing operations, fake update activity, cracked-software lures, and loader chains involving other malware or remote management tooling abuse. Reported distributors and operators associated with DarkGate delivery include TA571 and clusters linked to broader eCrime activity, and the malware has also been discussed in connection with Black Basta operations as a rented or shared capability.

DarkGate supports hands-on-keyboard post-compromise activity and has been used to enable persistence, lateral movement, and data exfiltration. Reported functionality includes clipboard capture, discovery of security products by process name for defensive awareness and behavior adjustment, installation into hidden directories, and searching for stored credentials associated with cryptocurrency wallets. Public reporting has also described variants or campaigns in which DarkGate supported stealer-like behavior and remote desktop capabilities such as HVNC and HAnyDesk.

Technically, DarkGate has been documented using APC-based execution techniques, including self-injection by queuing an APC locally and invoking NtTestAlert, as well as loader chains built with AutoIt. Some observed infections used user-executed scripts or installers that unpacked and launched DarkGate in memory, after which it could inject or stage additional payloads. In certain campaigns, DarkGate functioned as an intermediate loader or access-enablement component rather than the final objective, with follow-on malware deployed after initial execution.

DarkGate has appeared across a wide range of criminal delivery operations rather than a single exclusive actor set, making it part of the broader malware-as-a-service and access-brokering ecosystem. Its recurring use in phishing and ClickFix campaigns, combined with remote access, evasion, and collection features, makes it a flexible intrusion tool for initial footholds and subsequent post-exploitation on Windows systems.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Reported operators

Threat actors

7 named in public reporting
TA577

More recently, they have delivered Pikabot and DarkGate malware.

RastaFarEye

It appears that Black Basta had rented the DarkGate loader and HVNC from threat actor ‘Rastafareye’.

TA571

In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.

UNC4393

In late 2023, several months after the QAKBOT infrastructure takedown by the FBI and the United States Justice Department, UNC4393 began leveraging other distribution clusters for initial access, specifically those delivering DARKGATE, again via phishing.

BO Team

The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.

Storm-1607

These emails contained HTML attachments that attempted to install DarkGate, a commodity loader that is capable of keylogging, cryptocurrency mining, establishing C2 communications, and downloading additional malicious payloads, among others.

LAPSUS$

Associated Analytic Story DarkGate Malware

Exploited software

Vulnerabilities linked to DarkGate

1 CVEs

MITRE ATT&CK

DarkGate in ATT&CK

86 distinct techniques

Techniques

86 techniques
T1566 Phishing T1204 User Execution T1656 Impersonation T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1547.009 Shortcut Modification T1497.001 System Checks T1518.001 Security Software Discovery T1620 Reflective Code Loading T1560 Archive Collected Data T1055 Process Injection T1105 Ingress Tool Transfer T1059 Command and Scripting Interpreter T1055.012 Process Hollowing T1055.004 Asynchronous Procedure Call T1059.005 Visual Basic T1106 Native API T1059.001 PowerShell T1083 File and Directory Discovery T1140 Deobfuscate/Decode Files or Information T1119 Automated Collection T1027 Obfuscated Files or Information T1204.002 Malicious File T1564.001 Hidden Files and Directories T1555 Credentials from Password Stores T1115 Clipboard Data T1566.001 Spearphishing Attachment T1218.005 Mshta T1059.003 Windows Command Shell T1036 Masquerading T1203 Exploitation for Client Execution T1057 Process Discovery T1112 Modify Registry T1041 Exfiltration Over C2 Channel T1562 Impair Defenses T1592 Gather Victim Host Information T1555.004 Windows Credential Manager T1027.013 Encrypted/Encoded File T1070.004 File Deletion T1070 Indicator Removal T1490 Inhibit System Recovery T1547 Boot or Logon Autostart Execution T1562.001 Disable or Modify Tools T1071.001 Web Protocols T1218 System Binary Proxy Execution T1059.010 AutoHotKey & AutoIT T1614 System Location Discovery T1583.006 Web Services T1548.002 Bypass User Account Control T1539 Steal Web Session Cookie T1529 System Shutdown/Reboot T1497 Virtualization/Sandbox Evasion T1583.001 Domains T1560.001 Archive via Utility T1486 Data Encrypted for Impact T1036.003 Rename Legitimate Utilities T1136 Create Account T1218.009 Regsvcs/Regasm T1071.002 File Transfer Protocols T1047 Windows Management Instrumentation T1561.001 Disk Content Wipe T1480 Execution Guardrails T1010 Application Window Discovery T1566.002 Spearphishing Link T1657 Financial Theft T1680 Local Storage Discovery T1036.007 Double File Extension T1552 Unsecured Credentials T1098.007 Additional Local or Domain Groups T1569.002 Service Execution T1134.004 Parent PID Spoofing T1574.007 Path Interception by PATH Environment Variable T1056.001 Keylogging T1124 System Time Discovery T1001 Data Obfuscation T1496.001 Compute Hijacking T1005 Data from Local System T1021 Remote Services T1665 Hide Infrastructure T1622 Debugger Evasion T1071.004 DNS T1136.001 Local Account T1574.001 DLL T1574 Hijack Execution Flow T1219 Remote Access Tools T1071 Application Layer Protocol

Reporting

Research mentioning DarkGate

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.

Jul 16
Reversing Labs

ClickFix doesn't attack your knowledge. It attacks your trust. | RL Blog

Jul 15
Malware News

DriveSurge actor uses ClickFix and FakeUpdates to distribute malware via compromised websites - Malware News - Malware Analysis, News and Indicators

Jul 15
Malware News

Thousands of compromised websites abused by DriveSurge in active ClickFix and FakeUpdates campaigns - Malware News - Malware Analysis, News and Indicators

Jul 15
Help Net Security

ClickFix is changing the economics of social engineering - Help Net Security

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.