logo

DarkGate: Dancing the Samba With Alluring Excel Files

ID: 5ab98bfb-5e06-5958-9feb-2fcb7d82cf51

STIX ID: report--5ab98bfb-5e06-5958-9feb-2fcb7d82cf51

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-07-10

Date Updated: 2026-04-28

Author: Vishwa Thothathri, Yijie Sui, Anmol Maurya, Uday Pratap Singh and Brad Duncan

...
...

**Executive Summary:** This Unit 42 report analyzes a March–April 2024 DarkGate malware-as-a-service campaign using malicious Excel lures that reference public SMB shares to deliver VBS/JS → PowerShell → AutoHotkey loaders, resulting in an in-memory DarkGate backdoor with anti-VM/anti-analysis checks, observed data exfiltration, and multiple IoCs (SHA256 hashes, domains, and URLs), plus detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.