DarkGate Malware Being Spread Via Excel Docs Attached To Phishing Emails
ID: 608bfe51-2271-5b63-b4c6-c1b3e6d0f6c4
STIX ID: report--608bfe51-2271-5b63-b4c6-c1b3e6d0f6c4
Feed Name: KnowBe4 Blog
Cisco Talos researchers report a phishing campaign distributing the DarkGate malware through malicious Excel attachments that exploit Remote Template Injection to fetch and execute payloads. The attackers impersonate CEOs to coerce recipients into opening documents, have shifted to AutoHotKey scripting (from AutoIT) to avoid detection, and are also seen using Microsoft Teams and malvertising as distribution vectors, highlighting active, evolving tactics for information theft and evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
