logo

DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks

ID: b2653b89-79f5-5690-8d0b-881b86e65f13

STIX ID: report--b2653b89-79f5-5690-8d0b-881b86e65f13

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

DarkGate, a long-running malware-as-a-service, has evolved in version 6 to use AutoHotKey-based delivery chains (via malicious Excel/HTML phishing and chained macros/VBS/PowerShell) to fetch and execute a RAT that includes credential theft, rootkit, keylogging, screen capture, audio recording, and remote-control capabilities; campaigns leveraging CVE-2023-36025 and CVE-2024-21412 have targeted healthcare technology, telecommunications, and fintech organizations across the U.S., Europe, and Asia, with the operator 'RastaFarEye' selling subscriptions to a small group of customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.