DarkGate Malware Rented Out to Aspiring Hackers

A fresh malspam operation has been identified deploying a readily available malicious software known as DarkGate.

Telekom Security, in a recent report, stated that the increased activity of DarkGate malware can be reasonably attributed to the fact that its developer has recently begun renting it out to a select group of associates.

This latest report builds upon recent discoveries made by security researcher Igal Lytzki, who uncovered a campaign characterized by its large-scale nature. This campaign exploits compromised email threads to deceive recipients into downloading the malware.

The assault initiates with a deceptive URL in a phishing attempt. Upon clicking, this URL navigates through a traffic direction system (TDS), directing the victim to an MSI payload that is triggered under specific conditions. These conditions involve the presence of a refresh header within the HTTP response.

Upon opening the MSI file, a multi-step procedure is activated. This involves the use of an AutoIt script to execute shellcode, which serves as a conduit for decrypting and launching DarkGate through a crypter (or loader).

To be specific, the loader is engineered to dissect the AutoIt script and extract the encrypted malware instance. In an alternate version of the attacks, a Visual Basic Script is observed in place of the MSI file. This script, in turn, employs cURL to fetch the AutoIt executable and script file. The precise method of delivering the VB Script remains unknown.

DarkGate Sold on Dark Web

DarkGate, primarily marketed on underground forums by an individual known as RastaFarEye, possesses capabilities that enable it to elude detection by security software. It can establish persistence by making changes to the Windows Registry, escalate privileges, and pilfer data from web browsers and other applications such as Discord and FileZilla.

Furthermore, it establishes communication with a command-and-control (C2) server to list files, carry out data exfiltration, initiate cryptocurrency mining, remotely capture screenshots, and execute other commands.

This malware is available through a subscription model, with prices ranging from $1,000 per day to $15,000 per month, and even up to $100,000 per year. The author promotes it as the "ultimate tool for pentesters/redteamers" and highlights its unique features. Interestingly, earlier versions of DarkGate even included a ransomware module.

August 30, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.