logo

THREAT ALERT: DarkGate Loader

ID: b5dabc98-f31e-52ea-8e17-73b2b88c2468

STIX ID: report--b5dabc98-f31e-52ea-8e17-73b2b88c2468

Feed Name: Cybereason Blog

Threat Score
75/100

Date Published: 2024-01-29

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason warns of DarkGate Loader, an AutoIt-based loader distributed via phishing PDFs that decrypts and injects payloads to deploy post-exploitation tools (Cobalt Strike, Meterpreter). The alert describes a fast-moving infection chain with lateral movement to critical infrastructure, detection capabilities in the Cybereason platform, and recommended mitigations such as application control, variant payload prevention, hunting queries, and blocking IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.