logo

All You Need To Know About DarkGate Internals

ID: 6ba94063-8150-5e50-9f1e-ba25229dd103

STIX ID: report--6ba94063-8150-5e50-9f1e-ba25229dd103

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2023-11-20

Date Updated: 2026-07-20

...
...

**Executive Summary:** This technical report analyzes DarkGate, a modular loader/RAT offered as Malware-as-a-Service that provides reverse shells, hVNC, keylogging, Discord token theft, PowerShell execution, privilege escalation, and multiple evasion techniques (custom base64 alphabets, Union API/syscall usage, dynamic API resolution, LOLBAS DLL loading, APC injection), details its C2 communication and artifacts for hunting, and notes active use by multiple threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.