logo

DarkGate, the Swiss Army knife of malware, sees boom after rival Qbot crushed

ID: b038bc1c-25ad-5b72-ae05-4709fef3a893

STIX ID: report--b038bc1c-25ad-5b72-ae05-4709fef3a893

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-07-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

DarkGate is a modular malware-as-a-service that has increased in use since the QBot takedown; security firms report thousands of campaigns (Proofpoint documented ~14,000) and widespread abuse by criminal groups such as TA571. The family provides credential theft, keylogging, remote access and ransomware deployment, spreads via phishing, DLL sideloading and poisoned file shares, and employs advanced evasion (encryption, obfuscation, VM/AV checks); the report includes telemetry, IOCs and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.