THREAT ALERT: DarkGate Loader
ID: b5dabc98-f31e-52ea-8e17-73b2b88c2468
STIX ID: report--b5dabc98-f31e-52ea-8e17-73b2b88c2468
Feed Name: Cybereason Blog
Threat Score
Cybereason warns of DarkGate Loader, an AutoIt-based loader distributed via phishing PDFs that decrypts and injects payloads to deploy post-exploitation tools (Cobalt Strike, Meterpreter). The alert describes a fast-moving infection chain with lateral movement to critical infrastructure, detection capabilities in the Cybereason platform, and recommended mitigations such as application control, variant payload prevention, hunting queries, and blocking IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
