McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDarkGate | DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present. |
| T1047 Windows Management Instrumentation |
MalwareDarkGate | DarkGate has used WMI to execute files over the network and to obtain information about the domain. |
| T1055.012 Process Hollowing |
MalwareDarkGate | DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1056.001 Keylogging |
MalwareDarkGate | DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file. |
| T1057 Process Discovery |
MalwareDarkGate | DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values. |
| T1059.001 PowerShell |
MalwareDarkGate | DarkGate has used PowerShell to create a remote shell. |
| T1059.003 Windows Command Shell |
MalwareDarkGate | DarkGate uses a malicious Windows Batch script to run the Windows |
| T1070.004 File Deletion |
MalwareDarkGate | DarkGate has deleted its staging directories. |
| T1082 System Information Discovery |
MalwareDarkGate | DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount. |
| T1105 Ingress Tool Transfer |
MalwareDarkGate | DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the |
| T1106 Native API |
MalwareDarkGate | DarkGate uses the native Windows API |
| T1115 Clipboard Data |
MalwareDarkGate | DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file. |
| T1518.001 Security Software Discovery |
MalwareDarkGate | DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location. |
| T1529 System Shutdown/Reboot |
MalwareDarkGate | DarkGate has used the `shutdown`command to shut down and/or restart the victim system. |
| T1539 Steal Web Session Cookie |
MalwareDarkGate | DarkGate attempts to steal Opera cookies, if present, after terminating the related process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkGate | DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key. |
| T1561.001 Disk Content Wipe |
MalwareDarkGate | DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.