DarkGate, also known as MehCrypter, is a modular Windows malware loader sold as malware-as-a-service, with extensive remote-access and information-stealing capabilities. First publicly reported in 2018, it is implemented in Delphi and supports downloading and executing additional payloads, making it an initial-access tool for larger intrusions, including ransomware attacks. The underground seller RastaFarEye advertised access to DarkGate in 2023. Its users have included the BattleRoyal activity cluster, and Black Basta purchased access to the malware for its campaigns.
DarkGate supports password and browser-cookie theft, keylogging, screenshots, remote desktop access through VNC and hidden VNC, arbitrary command execution, directory browsing, and file retrieval. It collects host, user, running-program, and security-product information and can control cryptomining components. Credential collection targets browsers, email applications, Discord, and FileZilla, sometimes using legitimate password-recovery utilities. Persistence includes registry autorun mechanisms. DarkGate uses UAC bypass techniques and can obtain SYSTEM privileges, including for operations such as deleting system restore points.
Infection chains use phishing emails, stolen email threads, chat messages, fake invoices, malicious installers, fake browser updates, SEO poisoning, and ClickFix prompts. Campaigns have also used email flooding followed by IT-support impersonation. Delivery has abused Microsoft Teams and SharePoint and exploited Windows security-warning bypass vulnerabilities, including CVE-2023-36025, CVE-2024-21412, and CVE-2024-38213. Multistage execution commonly combines MSI packages, scripts, AutoIt, shellcode, and encrypted payloads. Evasion techniques include DLL side-loading through legitimate applications, process hollowing, hidden installation directories, custom encoding, and configurable debugger, sandbox, virtual-machine, memory, and disk checks. Campaigns have targeted organizations across numerous industries, including in the United States and Canada.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“When a user opens the internet shortcut file, it exploits CVE-2024-21412 to evade Microsoft Defender SmartScreen and triggers the execution of the LNK file hosted on the same WebDAV share.” The content also uses CVE-2024-21212 once for this same infection step; this appears to be a typographical error rather than a separate vulnerability.
이 취약점은 DarkGate 캠페인과 같은 실제 공격에서 악용되었다.
Additionally, the .URL files involved exploited CVE-2023-36025, a vulnerability in Windows SmartScreen. ... The vulnerability could allow an actor to bypass the SmartScreen defenses if a user clicked on a specially crafted .URL file or a hyperlink pointing to a .URL file. | Throughout the summer and fall of 2023, DarkGate entered the ring competing for the top spot in the remote access trojan (RAT) and loader category. It was observed in use by multiple cybercrime actors... DarkGate can be used to steal information and download additional malware payloads.
— Privilege Escalation using CVE-2021–1733 or Process Hollowing ... DarkGate attempts to escalate privileges in two ways. One method is using PsExec to obtain SYSTEM privileges(CVE-2021–1733), and the other method is the Process Hollowing method. | DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DarkGate is sold as malware-as-a-service and spreads through phishing, including chat messages.
Further analysis confirmed this initial attribution, since embedded strings and contained functionality clearly identified the sample as part of the DarkGate malware family.
“Since the TA571 / DarkGate campaign in 2024, one of the earliest documented usages of this technique, ClickFix campaigns have garnered widespread popularity among threat actors.”
Throughout the summer and fall of 2023, DarkGate entered the ring competing for the top spot in the remote access trojan (RAT) and loader category. It was observed in use by multiple cybercrime actors... DarkGate can be used to steal information and download additional malware payloads.
Cardinal has since resumed attacks and now appears to have switched to working with the operators of the DarkGate loader to obtain access to potential victims.
DarkGate is a malware that has been developed since 2017 and sold as Malware-as-a-Service. DarkGate supports attackers able to do malicious acts to victims listed below. — Remote Code Execution by Reverse Shell or Remote Desktop such as VNC and AnyDesk. — Data Exfiltration on saved files, browser cookies, or cached passwords. — Cryptocurrency Mining using XMRig — Privilege Escalation using CVE-2021–1733 or Process Hollowing — Persistence Management for DarkGate itself
50 distinct techniques documented for this family, organized by ATT&CK tactic.
362 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
196 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-service loader and remote-access tool distributed through phishing and chat messages. Described as an alternative initial-access source used by Black Basta following QakBot's disruption.
The article characterizes DarkGate as an example of an infostealer executed through ClickFix-induced PowerShell commands. It does not describe DarkGate-specific capabilities or provide evidence of a particular campaign.
Malware / Outils # Sauron Loader (loader) DarkGate (loader) LockBit (ransomware) ...
Mentioned solely as malware delivered in earlier campaigns using a similar email-bombing and vishing technique.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.