ATT&CKReferencesEnsilo Darkgate 2018

Ensilo Darkgate 2018

Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareDarkGate

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

T1010
Application Window Discovery
MalwareDarkGate

DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the FindWindow API function.

T1027.013
Encrypted/Encoded File
MalwareDarkGate

DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads.

T1036
Masquerading
MalwareDarkGate

DarkGate can masquerade as pirated media content for initial delivery to victims.

T1041
Exfiltration Over C2 Channel
MalwareDarkGate

DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials.

T1055.012
Process Hollowing
MalwareDarkGate

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.

T1056.001
Keylogging
MalwareDarkGate

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.

T1057
Process Discovery
MalwareDarkGate

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.

T1059.005
Visual Basic
MalwareDarkGate

DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim.

T1059.010
AutoHotKey & AutoIT
MalwareDarkGate

DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`.

T1071.004
DNS
MalwareDarkGate

DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques.

T1082
System Information Discovery
MalwareDarkGate

DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount.

T1083
File and Directory Discovery
MalwareDarkGate

Some versions of DarkGate search for the hard-coded folder C:\Program Files\e Carte Bleue.

T1098.007
Additional Local or Domain Groups
MalwareDarkGate

DarkGate elevates accounts created through the malware to the local administration group during execution.

T1105
Ingress Tool Transfer
MalwareDarkGate

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads. DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1106
Native API
MalwareDarkGate

DarkGate uses the native Windows API CallWindowProc() to decode and launch encoded shellcode payloads during execution. DarkGate can call kernel mode functions directly to hide the use of process hollowing methods during execution. DarkGate has also used the `CreateToolhelp32Snapshot`, `GetFileAttributesA` and `CreateProcessA` functions to obtain a list of running processes, to check for security products and to execute its malware.

T1115
Clipboard Data
MalwareDarkGate

DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file.

T1119
Automated Collection
MalwareDarkGate

DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified.

T1124
System Time Discovery
MalwareDarkGate

DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation.

T1136.001
Local Account
MalwareDarkGate

DarkGate creates a local user account, SafeMode, via net user commands.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkGate

DarkGate installation includes binary code stored in a file located in a hidden directory, such as shell.txt, that is decrypted then executed. DarkGate uses hexadecimal-encoded shellcode payloads during installation that are called via Windows API CallWindowProc() to decode and then execute.

T1204.002
Malicious File
MalwareDarkGate

DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.

T1486
Data Encrypted for Impact
MalwareDarkGate

DarkGate can deploy follow-on ransomware payloads.

T1490
Inhibit System Recovery
MalwareDarkGate

DarkGate can delete system restore points through the command cmd.exe /c vssadmin delete shadows /for=c: /all /quiet”.

T1496.001
Compute Hijacking
MalwareDarkGate

DarkGate can deploy follow-on cryptocurrency mining payloads.

T1497.001
System Checks
MalwareDarkGate

DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment.

T1518.001
Security Software Discovery
MalwareDarkGate

DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkGate

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key.

T1548.002
Bypass User Account Control
MalwareDarkGate

DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges.

T1552
Unsecured Credentials
MalwareDarkGate

DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe.

T1564.001
Hidden Files and Directories
MalwareDarkGate

DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`.

T1566.001
Spearphishing Attachment
MalwareDarkGate

DarkGate can be distributed through emails with malicious attachments from a spoofed email address.

T1574
Hijack Execution Flow
MalwareDarkGate

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script. When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

T1574.007
Path Interception by PATH Environment Variable
MalwareDarkGate

DarkGate overrides the %windir% environment variable by setting a Registry key, HKEY_CURRENT_User\Environment\windir, to an alternate command to execute a malicious AutoIt script. This allows DarkGate to run every time the scheduled task DiskCleanup is executed as this uses the path value %windir%\system32\cleanmgr.exe for execution.

T1614
System Location Discovery
MalwareDarkGate

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

T1657
Financial Theft
MalwareDarkGate

DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets.

T1680
Local Storage Discovery
MalwareDarkGate

DarkGate uses the Delphi methods Sysutils::DiskSize and GlobalMemoryStatusEx to collect disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment.

T1685
Disable or Modify Tools
MalwareDarkGate

DarkGate will terminate processes associated with several security software products if identified during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.