logo

DarkGate Malware Being Spread Via Excel Docs Attached To Phishing Emails

ID: 608bfe51-2271-5b63-b4c6-c1b3e6d0f6c4

STIX ID: report--608bfe51-2271-5b63-b4c6-c1b3e6d0f6c4

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Cisco Talos researchers report a phishing campaign distributing the DarkGate malware through malicious Excel attachments that exploit Remote Template Injection to fetch and execute payloads. The attackers impersonate CEOs to coerce recipients into opening documents, have shifted to AutoHotKey scripting (from AutoIT) to avoid detection, and are also seen using Microsoft Teams and malvertising as distribution vectors, highlighting active, evolving tactics for information theft and evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.