DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks
ID: b2653b89-79f5-5690-8d0b-881b86e65f13
STIX ID: report--b2653b89-79f5-5690-8d0b-881b86e65f13
Feed Name: The Hacker News
DarkGate, a long-running malware-as-a-service, has evolved in version 6 to use AutoHotKey-based delivery chains (via malicious Excel/HTML phishing and chained macros/VBS/PowerShell) to fetch and execute a RAT that includes credential theft, rootkit, keylogging, screen capture, audio recording, and remote-control capabilities; campaigns leveraging CVE-2023-36025 and CVE-2024-21412 have targeted healthcare technology, telecommunications, and fintech organizations across the U.S., Europe, and Asia, with the operator 'RastaFarEye' selling subscriptions to a small group of customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
