Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareDarkGate | DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes. |
| T1027.013 Encrypted/Encoded File |
MalwareDarkGate | DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads. |
| T1036.003 Rename Legitimate Utilities |
MalwareDarkGate | DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the |
| T1036.007 Double File Extension |
MalwareDarkGate | DarkGate masquerades malicious LNK files as PDF objects using the double extension |
| T1059.003 Windows Command Shell |
MalwareDarkGate | DarkGate uses a malicious Windows Batch script to run the Windows |
| T1105 Ingress Tool Transfer |
MalwareDarkGate | DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the |
| T1106 Native API |
MalwareDarkGate | DarkGate uses the native Windows API |
| T1124 System Time Discovery |
MalwareDarkGate | DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation. |
| T1134.004 Parent PID Spoofing |
MalwareDarkGate | DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkGate | DarkGate installation includes binary code stored in a file located in a hidden directory, such as |
| T1204.002 Malicious File |
MalwareDarkGate | DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution. |
| T1480 Execution Guardrails |
MalwareDarkGate | DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them. |
| T1555 Credentials from Password Stores |
MalwareDarkGate | DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions. |
| T1566.002 Spearphishing Link |
MalwareDarkGate | DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads. |
| T1569.002 Service Execution |
MalwareDarkGate | DarkGate tries to elevate privileges to |
| T1574.001 DLL |
MalwareDarkGate | DarkGate includes one infection vector that leverages a malicious "KeyScramblerE.DLL" library that will load during the execution of the legitimate KeyScrambler application. |
| T1583.001 Domains |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1622 Debugger Evasion |
MalwareDarkGate | DarkGate checks the |
| T1665 Hide Infrastructure |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.