logo

DarkGate Malware Targets Excel Files & SMB Shares

ID: 1a472db6-52ac-547c-833f-afae2fa31a22

STIX ID: report--1a472db6-52ac-547c-833f-afae2fa31a22

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-07-12

Date Updated: 2026-04-19

Author: Kaaviya

...
...

DarkGate (Mar–Apr 2024) is a widespread malware campaign that leveraged exposed Samba/SMB file shares and malicious Excel documents to download VBS/JS and PowerShell stagers that deploy an AutoHotKey-based loader. The malware uses anti-analysis checks (VM/CPU checks, AV scanning), obfuscated shellcode, XOR-based configuration variations, unencrypted Base64 HTTP C2 channels, and large data exfiltration via HTTP POST; it operates as a MaaS and has targeted victims across North America, Europe, and Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.