DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks
The final stages of DarkGate malware-as-a-service (MaaS) attacks are now being delivered by an AutoHotkey method rather than AutoIt scripts, highlighting the threat actors' ongoing efforts to stay one step ahead of detection.
The software's developer, RastaFarEye, has been observing updates in DarkGate version 6, which was launched in March 2024. Up to 30 consumers have been subscribing to the application. At least 2018 has seen the malware's active phase.
DarkGate is a feature-rich remote access trojan (RAT) that includes modules for screen capture, keylogging, credential theft, and remote desktop. It also has rootkit and command-and-control (C2) capabilities.
In an attempt to evade security solutions, DarkGate campaigns have a tendency to adapt very quickly read more DarkGate M...

