Malware.View on attack.mitre.org
DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining. |
| T1005 Data from Local System |
DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present. |
| T1010 Application Window Discovery |
DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the |
| T1027 Obfuscated Files or Information |
DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes. |
| T1027.013 Encrypted/Encoded File |
DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads. |
| T1036 Masquerading |
DarkGate can masquerade as pirated media content for initial delivery to victims. |
| T1036.003 Rename Legitimate Utilities |
DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the |
| T1036.007 Double File Extension |
DarkGate masquerades malicious LNK files as PDF objects using the double extension |
| T1041 Exfiltration Over C2 Channel |
DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials. |
| T1047 Windows Management Instrumentation |
DarkGate has used WMI to execute files over the network and to obtain information about the domain. |
| T1055.012 Process Hollowing |
DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1056.001 Keylogging |
DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file. |
| T1057 Process Discovery |
DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values. |
| T1059.001 PowerShell |
DarkGate has used PowerShell to create a remote shell. |
| T1059.003 Windows Command Shell |
DarkGate uses a malicious Windows Batch script to run the Windows |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.