Throughout the summer and fall of 2023, DarkGate entered the ring competing for the top spot in the remote access trojan (RAT) and loader category. It was observed in use by multiple cybercrime actors... DarkGate can be used to steal information and download additional malware payloads.
DarkGate
DarkGate is a Windows malware family widely characterized as a malware-as-a-service remote access trojan and loader that has been active since at least 2018.
Profile source: Mallory opens in a new tabDarkGate
Family profile
DarkGate is a Windows malware family widely characterized as a malware-as-a-service remote access trojan and loader that has been active since at least 2018. It is associated with the underground operator known as RastaFarEye and has been used by multiple cybercrime actors as an initial-access and post-compromise tool. DarkGate has been linked to broad criminal operations, including campaigns overlapping with Black Basta intrusion activity, and has been delivered at scale across many industries, with notable targeting observed in North America and Europe.
DarkGate provides a broad feature set for full compromise of infected Windows systems. Reported capabilities include remote access, downloading and executing additional payloads, information stealing, browser data theft, keylogging, screen capture, hidden virtual network computing, and use as a staging platform for follow-on malware such as ransomware and cryptominers. It also supports persistence through Startup-folder artifacts and Run-key mechanisms. Some variants perform security-software discovery by checking for defensive products and may alter execution behavior based on what is found.
The malware is notable for layered evasion and in-memory execution. Observed samples use AutoIt- or AutoHotKey-based stages, shellcode loaders, custom encoding and decryption routines, and process hollowing or related injection techniques to execute payloads inside legitimate Windows processes. DarkGate has also used DLL side-loading, including abuse of legitimate signed applications to load malicious libraries. Additional tradecraft documented across variants includes hidden directories for dropped components, anti-analysis and anti-VM checks, environment checks, and multiple User Account Control bypass techniques for privilege escalation.
DarkGate has been distributed through diverse delivery chains. Common vectors include phishing emails with malicious attachments or links, fake browser-update lures, malicious PDF-to-MSI chains, Microsoft Teams social-engineering campaigns, SharePoint-hosted payloads, Excel attachments using remote template injection, and Excel add-in files. SEO poisoning and attacker-controlled download pages have also been used to drive victims to trojanized installers. MSI-based installers and script-driven loaders are especially prominent in recent campaigns.
Operationally, DarkGate occupies the space between a loader and a full-featured RAT. It is frequently used to establish footholds, steal data, and deploy additional malware, making it attractive to financially motivated actors seeking flexible access tooling. Its rapid iteration, varied infection chains, and combination of credential theft, surveillance, persistence, privilege escalation, and defense evasion have made it a prominent Windows threat in contemporary cybercrime activity.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Initial Access
- Keylogging
- Persistence
- Post Exploitation
- Privilege Escalation
- Process Injection
- Reconnaissance
Reported operators
Threat actors
13 named in public reportingCardinal has since resumed attacks and now appears to have switched to working with the operators of the DarkGate loader to obtain access to potential victims.
First discovered in 2018, DarkGate is a Remote Access Trojan (RAT) that enables attackers to fully compromise victim systems. The software is developed and sold as Malware-as-a-Service (MaaS) by an actor known as RastaFarEye on underground cybercrime forums.
DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
Specifically, our SOC frequently saw Black Basta sign Pikabot and Darkgate malware they used in phishing campaigns.
DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
In addition, TA571 has been associated with the distribution of other malware families, including variants of IcedID, NetSupportRAT, DarkGate and others.
In late 2023, several months after the QAKBOT infrastructure takedown by the FBI and the United States Justice Department, UNC4393 began leveraging other distribution clusters for initial access, specifically those delivering DARKGATE, again via phishing.
The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.
These emails contained HTML attachments that attempted to install DarkGate, a commodity loader that is capable of keylogging, cryptocurrency mining, establishing C2 communications, and downloading additional malicious payloads, among others.
Associated Analytic Story DarkGate Malware
Exploited software
Vulnerabilities linked to DarkGate
3 CVEsMITRE ATT&CK
DarkGate in ATT&CK
124 distinct techniquesTechniques
124 techniquesReporting
Research mentioning DarkGate
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework | TrendAI (US)
TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.
Post by @lazarusholic.bsky.social - Bluesky
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Incident response statistics and cases at educational institutions in Brazil | Securelist
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT
Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Windows Suspicious Child Of Consent.exe | Splunk Security Content
ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille
Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.