DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign
ID: d79ca0c1-9090-507f-b642-8cd4e86353f5
STIX ID: report--d79ca0c1-9090-507f-b642-8cd4e86353f5
Feed Name: The Hacker News
Threat Score
**Executive summary:** Palo Alto Networks Unit 42 analyzed a short-lived March–April 2024 DarkGate campaign that used public Samba file shares hosting VBS/JavaScript and weaponized Excel files to fetch PowerShell and an AutoHotKey DarkGate payload, enabling remote control, reverse shells, and other post-compromise actions; Proofpoint additionally linked TA571 spam activity and reported large-scale distribution attempts and use of DarkGate as an initial access broker.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
