DarkGate: Opening Gates for Financially Motivated Threat Actors
ID: be82ac02-d146-5664-9c28-af0bd2c5c221
STIX ID: report--be82ac02-d146-5664-9c28-af0bd2c5c221
Feed Name: EclecticIQ
EclecticIQ analysts report on the DarkGate loader (including version 6.1.6), detailing its capabilities (hVNC, keylogging, rootkit, polymorphic shellcode), evolving delivery methods (LOLBAS, AutoIt scripts, DNS TXT, Google DoubleClick open redirect, MSI/CAB/ZIP distribution, DLL side‑loading), and operational use by financially motivated actors and ransomware affiliates targeting financial institutions; the blog provides technical analysis, IOCs, detection recommendations, and a YARA rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
