DarkGate Malware Targets Excel Files & SMB Shares
ID: 1a472db6-52ac-547c-833f-afae2fa31a22
STIX ID: report--1a472db6-52ac-547c-833f-afae2fa31a22
Feed Name: Cyber Press
DarkGate (Mar–Apr 2024) is a widespread malware campaign that leveraged exposed Samba/SMB file shares and malicious Excel documents to download VBS/JS and PowerShell stagers that deploy an AutoHotKey-based loader. The malware uses anti-analysis checks (VM/CPU checks, AV scanning), obfuscated shellcode, XOR-based configuration variations, unencrypted Base64 HTTP C2 channels, and large data exfiltration via HTTP POST; it operates as a MaaS and has targeted victims across North America, Europe, and Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
