RastaFarEye is an underground malware developer and operator of the DarkGate malware-as-a-service platform. The actor began publicly advertising DarkGate on cybercrime forums in June 2023, offering subscriptions priced at up to USD 15,000 per month or USD 100,000 per year. The actor’s country of origin is unconfirmed. No additional aliases or named subgroups are established. DarkGate is a Delphi-based remote access trojan supporting credential and browser-cookie theft, keylogging, screen capture, remote desktop access, command execution, file collection, cryptocurrency mining, and persistence. Its execution chains have combined malicious installers and scripts with legitimate AutoIt interpreters, encoded shellcode, in-memory loaders, and DLL side-loading. Defense-evasion features include process hollowing, parent-process identifier spoofing, antivirus discovery, and configurable checks for debuggers, virtual machines, sandboxes, and other analysis environments. Persistence mechanisms include registry Run keys and Startup folder placement. The malware also supports privilege elevation and uses legitimate password-recovery utilities to obtain credentials. DarkGate customer campaigns have used phishing messages incorporating stolen email threads and Microsoft Teams messages impersonating executives. Observed activity includes an attack against the holding company of Trellix and Skyhigh Security, with substantial detections in the United States, Germany, Italy, Malaysia, and Singapore. These deployments belong to the wider customer ecosystem and should not automatically be attributed to RastaFarEye personally. The developer has repeatedly revised DarkGate’s loaders, configuration encoding, and evasion features following public technical analysis. The actor’s commercial subscription model supports a financial motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
157 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer and operator behind the DarkGate malware-as-a-service offering, continuously updating the malware to improve evasion, anti-analysis, delivery, and endpoint security bypass capabilities for customers conducting global compromises.
Identified as the known operator and developer behind the DarkGate MaaS platform.
Reportedly the sole developer of DarkGate, claiming development since 2017. Previously used the malware privately and subsequently began offering malware-as-a-service access to a maximum of 10 affiliates, with advertised prices of $1,000 per day, $15,000 per month, or $100,000 per year. Provides updates and demonstrations of its builder and administration panel. The report does not establish that RastaFarEye personally operated the observed phishing campaigns. Language and apparent VPN-location evidence do not establish the actor's country of origin.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.