logo

DarkGate switches up its tactics with new payload, email templates

ID: 8cd358e3-9007-523e-82db-d3d333b14f98

STIX ID: report--8cd358e3-9007-523e-82db-d3d333b14f98

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-06-05

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos describes an active DarkGate malspam campaign (March 2024) that uses malicious Excel attachments with Remote Template Injection to pull remote VBS/PowerShell stages from attacker-controlled SMB/HTTP servers. The operators switched from AutoIT to AutoHotKey to load base64-encoded shellcode and execute the final DarkGate payload in-memory (avoiding disk writes), establish persistence via a startup shortcut, and target U.S. organizations—most frequently healthcare technologies and telecommunications—while Talos provides IOCs and detections for Cisco products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.