DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign
Researchers studying cybersecurity have provided insight into a brief campaign of DarkGate malware that spread by using Samba file shares.
The activity, according to Palo Alto Networks Unit 42, took place between March and April of 2024. The infection chains used servers that were public-facing Samba file shares that hosted JavaScript and Visual Basic Script (VBS) files. North America, Europe, and portions of Asia were among the targets.
This was a very short-lived campaign, according to security researchers Brad Duncan, Yijie Sui, Anmol Maurya, Uday Pratap Singh, and Vishwa Thothathri, that shows how threat actors can inventively misuse reputable tools and services to spread their malware.
Since its inception in 2018, DarkGate has developed into a malware-as-a-service (MaaS) pro...

