Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareDarkGate | DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining. |
| T1010 Application Window Discovery |
MalwareDarkGate | DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the |
| T1027.013 Encrypted/Encoded File |
MalwareDarkGate | DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads. |
| T1036 Masquerading |
MalwareDarkGate | DarkGate can masquerade as pirated media content for initial delivery to victims. |
| T1041 Exfiltration Over C2 Channel |
MalwareDarkGate | DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials. |
| T1055.012 Process Hollowing |
MalwareDarkGate | DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1056.001 Keylogging |
MalwareDarkGate | DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file. |
| T1057 Process Discovery |
MalwareDarkGate | DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values. |
| T1059.005 Visual Basic |
MalwareDarkGate | DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim. |
| T1059.010 AutoHotKey & AutoIT |
MalwareDarkGate | DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`. |
| T1071.004 DNS |
MalwareDarkGate | DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. |
| T1082 System Information Discovery |
MalwareDarkGate | DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount. |
| T1083 File and Directory Discovery |
MalwareDarkGate | Some versions of DarkGate search for the hard-coded folder |
| T1098.007 Additional Local or Domain Groups |
MalwareDarkGate | DarkGate elevates accounts created through the malware to the local administration group during execution. |
| T1105 Ingress Tool Transfer |
MalwareDarkGate | DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the |
| T1106 Native API |
MalwareDarkGate | DarkGate uses the native Windows API |
| T1115 Clipboard Data |
MalwareDarkGate | DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file. |
| T1119 Automated Collection |
MalwareDarkGate | DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified. |
| T1124 System Time Discovery |
MalwareDarkGate | DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation. |
| T1136.001 Local Account |
MalwareDarkGate | DarkGate creates a local user account, |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkGate | DarkGate installation includes binary code stored in a file located in a hidden directory, such as |
| T1204.002 Malicious File |
MalwareDarkGate | DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution. |
| T1486 Data Encrypted for Impact |
MalwareDarkGate | DarkGate can deploy follow-on ransomware payloads. |
| T1490 Inhibit System Recovery |
MalwareDarkGate | DarkGate can delete system restore points through the command |
| T1496.001 Compute Hijacking |
MalwareDarkGate | DarkGate can deploy follow-on cryptocurrency mining payloads. |
| T1497.001 System Checks |
MalwareDarkGate | DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment. |
| T1518.001 Security Software Discovery |
MalwareDarkGate | DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkGate | DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key. |
| T1548.002 Bypass User Account Control |
MalwareDarkGate | DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges. |
| T1552 Unsecured Credentials |
MalwareDarkGate | DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe. |
| T1564.001 Hidden Files and Directories |
MalwareDarkGate | DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`. |
| T1566.001 Spearphishing Attachment |
MalwareDarkGate | DarkGate can be distributed through emails with malicious attachments from a spoofed email address. |
| T1574 Hijack Execution Flow |
MalwareDarkGate | DarkGate edits the Registry key |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareDarkGate | DarkGate overrides the |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1657 Financial Theft |
MalwareDarkGate | DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets. |
| T1680 Local Storage Discovery |
MalwareDarkGate | DarkGate uses the Delphi methods |
| T1685 Disable or Modify Tools |
MalwareDarkGate | DarkGate will terminate processes associated with several security software products if identified during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.