DarkGate: Dancing the Samba With Alluring Excel Files
ID: 5ab98bfb-5e06-5958-9feb-2fcb7d82cf51
STIX ID: report--5ab98bfb-5e06-5958-9feb-2fcb7d82cf51
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-07-10
Date Updated: 2026-04-28
Author: Vishwa Thothathri, Yijie Sui, Anmol Maurya, Uday Pratap Singh and Brad Duncan
**Executive Summary:** This Unit 42 report analyzes a March–April 2024 DarkGate malware-as-a-service campaign using malicious Excel lures that reference public SMB shares to deliver VBS/JS → PowerShell → AutoHotkey loaders, resulting in an in-memory DarkGate backdoor with anti-VM/anti-analysis checks, observed data exfiltration, and multiple IoCs (SHA256 hashes, domains, and URLs), plus detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
