DarkGate switches up its tactics with new payload, email templates
ID: 8cd358e3-9007-523e-82db-d3d333b14f98
STIX ID: report--8cd358e3-9007-523e-82db-d3d333b14f98
Feed Name: Cisco Talos
Cisco Talos describes an active DarkGate malspam campaign (March 2024) that uses malicious Excel attachments with Remote Template Injection to pull remote VBS/PowerShell stages from attacker-controlled SMB/HTTP servers. The operators switched from AutoIT to AutoHotKey to load base64-encoded shellcode and execute the final DarkGate payload in-memory (avoiding disk writes), establish persistence via a startup shortcut, and target U.S. organizations—most frequently healthcare technologies and telecommunications—while Talos provides IOCs and detections for Cisco products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
