DarkGate

S1111

Malware.View on attack.mitre.org

About this malware

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.

Techniques used58

Procedure examples58

TechniqueProcedure example
T1001
Data Obfuscation

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

T1005
Data from Local System

DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1010
Application Window Discovery

DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the FindWindow API function.

T1027
Obfuscated Files or Information

DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes.

T1027.013
Encrypted/Encoded File

DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads.

T1036
Masquerading

DarkGate can masquerade as pirated media content for initial delivery to victims.

T1036.003
Rename Legitimate Utilities

DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\\ root directory that copies and renames the legitimate Windows <curl>curl</code> command to this new location.

T1036.007
Double File Extension

DarkGate masquerades malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1041
Exfiltration Over C2 Channel

DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials.

T1047
Windows Management Instrumentation

DarkGate has used WMI to execute files over the network and to obtain information about the domain.

T1055.012
Process Hollowing

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.

T1056.001
Keylogging

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.

T1057
Process Discovery

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.

T1059.001
PowerShell

DarkGate has used PowerShell to create a remote shell.

T1059.003
Windows Command Shell

DarkGate uses a malicious Windows Batch script to run the Windows code utility to retrieve follow-on script payloads. DarkGate has also used `cmd.exe` to create a remote shell.

View all 58 procedure examples

Groups that use it0

None recorded.

Campaigns1

References2

  1. Ensilo Darkgate 2018 Open source
    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.
  2. Trellix Darkgate 2023 Open source
    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.