logo

DarkGate: Opening Gates for Financially Motivated Threat Actors

ID: be82ac02-d146-5664-9c28-af0bd2c5c221

STIX ID: report--be82ac02-d146-5664-9c28-af0bd2c5c221

Feed Name: EclecticIQ

Threat Score
78/100

Date Published: 2024-02-12

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

EclecticIQ analysts report on the DarkGate loader (including version 6.1.6), detailing its capabilities (hVNC, keylogging, rootkit, polymorphic shellcode), evolving delivery methods (LOLBAS, AutoIt scripts, DNS TXT, Google DoubleClick open redirect, MSI/CAB/ZIP distribution, DLL side‑loading), and operational use by financially motivated actors and ransomware affiliates targeting financial institutions; the blog provides technical analysis, IOCs, detection recommendations, and a YARA rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.