Tag: DarkGate Malware

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
News

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware

Microsoft Teams has been used in a recent social engineering campaign to help spread the known malware known as DarkGate. Researchers Catherine Loveria, Jovit Samaniego, and Gabriel Nicoleta of Trend Micro claimed that an attacker impersonated a user's client and obtained remote access to their machine through social engineering during a Microsoft Teams call. The attacker successfully directed the victim to download AnyDesk, a frequently used remote access program, but was unable to install a Microsoft Remote Support application. According to a recent report by cybersecurity company Rapid7, the attack entailed flooding a target's email inbox with thousands of emails read more about Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware. Get up to date on the ...
DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign
News

DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign

Researchers studying cybersecurity have provided insight into a brief campaign of DarkGate malware that spread by using Samba file shares. The activity, according to Palo Alto Networks Unit 42, took place between March and April of 2024. The infection chains used servers that were public-facing Samba file shares that hosted JavaScript and Visual Basic Script (VBS) files. North America, Europe, and portions of Asia were among the targets. This was a very short-lived campaign, according to security researchers Brad Duncan, Yijie Sui, Anmol Maurya, Uday Pratap Singh, and Vishwa Thothathri, that shows how threat actors can inventively misuse reputable tools and services to spread their malware. Since its inception in 2018, DarkGate has developed into a malware-as-a-service (MaaS) pro...
DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks
News

DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks

The final stages of DarkGate malware-as-a-service (MaaS) attacks are now being delivered by an AutoHotkey method rather than AutoIt scripts, highlighting the threat actors' ongoing efforts to stay one step ahead of detection. The software's developer, RastaFarEye, has been observing updates in DarkGate version 6, which was launched in March 2024. Up to 30 consumers have been subscribing to the application. At least 2018 has seen the malware's active phase. DarkGate is a feature-rich remote access trojan (RAT) that includes modules for screen capture, keylogging, credential theft, and remote desktop. It also has rootkit and command-and-control (C2) capabilities. In an attempt to evade security solutions, DarkGate campaigns have a tendency to adapt very quickly read more DarkGate M...
Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware
News

Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware

Attacks using the commodity malware DarkGate that target organizations in the U.S., India, and the U.K. have been connected to Vietnamese criminals who are known to use the infamous Ducktail stealer. WithSecure stated in a report released today that "the overlap of tools and campaigns is very likely due to the effects of a cybercrime marketplace." "Threat actors are able to acquire and use multiple different tools for the same purpose, and all they have to do is come up with targets, campaigns, and lures." The development coincides with an increase in malware campaigns that use DarkGate in recent months, mostly due to its creator's choice to sell it to other threat actors for malware-as-a-service (MaaS) after utilizing it for personal use since 2018 read more Vietnamese Hackers Targ...
DarkGate malware spreads through compromised Skype accounts
News

DarkGate malware spreads through compromised Skype accounts

DarkGate malware assaults have been using hacked Skype accounts to infect targets with attachments that contain VBA loader scripts between July and September. Trend Micro security experts, who saw the attacks, claim that this script downloads an AutoIT script that is intended to drop and run the last payload of the DarkGate malware. "Access to the victim's Skype account allowed the actor to hijack an existing messaging thread and craft the naming convention of the files to relate to the context of the chat history," Trend Micro stated read more DarkGate malware spreads through compromised Skype accounts. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and solutions.
DarkGate Malware Spreading via Messaging Services Posing as PDF Files
News

DarkGate Malware Spreading via Messaging Services Posing as PDF Files

It has been noted that the malware known as DarkGate is disseminated using instant messaging services like Microsoft Teams and Skype. In these attacks, a loader script for Visual Basic for Applications (VBA) is delivered through messaging apps in the guise of a PDF document. When the PDF is read, an AutoIt script that launches malware is downloaded and executed. "It's unclear how the originating accounts of the instant messaging applications were compromised, however it is hypothesized to be either through leaked credentials available through underground forums or the previous compromise of the parent organization," Trend Micro stated in a fresh analysis released Thursday read more DarkGate Malware Spreading via Messaging Services Posing as PDF Files. Stay informed with the best ...
DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates
News

DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates

A brand-new malspam operation has been seen using DarkGate, a type of commercial malware. According to a study from Telekom Security last week, "the current spike in DarkGate malware activity is plausible given the fact that the malware developer has recently started to rent out the malware to a small number of affiliates." The most recent study expands on prior discoveries made by security researcher Igal Lytzki, who described a "high volume campaign" that makes use of hacked email threads to deceive recipients into installing malware read more DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and solu...