LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

EnterpriseS1111MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DarkGate matters because MITRE describes it as a Windows malware family used for initial access and data gathering, with associations to credential theft, cryptomining, cryptotheft, and pre-ransomware activity. For leaders, the practical issue is not a single signature; it is whether Windows endpoint, identity, scripting, DNS, and command-and-control monitoring can connect early execution and discovery behaviors to later data theft or ransomware-preparation risk.

Executive priority

Prioritize DarkGate as a resilience and readiness test for Windows environments: can the organization detect suspicious scripting, masqueraded files, credential collection, C2 over DNS, tool transfer, data collection, and exfiltration over C2 before business disruption occurs? Because MITRE lists DarkGate as Malware-as-a-Service and under active development, leadership should expect variation and ask for evidence-based coverage across behavior patterns, not just static indicators.

Technical view

ATT&CK provides no official detection text for S1111, so SOC and IR teams should validate coverage through the related techniques. Focus on Windows execution through PowerShell, cmd, Visual Basic, AutoHotKey/AutoIT, and WMI; defense evasion through obfuscated or encoded files, masquerading, double extensions, renamed utilities, process hollowing, and file deletion; discovery of processes, files, directories, system information, and application windows; credential collection via keylogging; C2 using obfuscation and DNS; ingress tool transfer; and exfiltration over the C2 channel. Treat these as behavior clusters that should be correlated across endpoint, identity, and network telemetry.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • PowerShell, Windows command shell, WMI, Visual Basic, AutoHotKey, and AutoIT execution logs where available
  • File creation, rename, deletion, extension, and encoded/obfuscated artifact metadata
  • Process injection or process hollowing-related endpoint alerts or memory telemetry
  • DNS query and response logs, including unusual volume, domains, timing, or encoded-looking labels

Detection direction

  • Validate correlation rules that join scripting or WMI execution with subsequent discovery, file manipulation, network beaconing, or tool transfer.
  • Tune for masquerading patterns such as double extensions and renamed utilities, while accounting for legitimate administration and software packaging activity.
  • Review DNS monitoring for C2-like behavior, but avoid relying only on domain reputation because ATT&CK notes data obfuscation and DNS-based communications.
  • Hunt for suspicious process hollowing or unusual parent-child process relationships on Windows endpoints.
  • Monitor group membership changes as persistence or privilege-escalation evidence, especially when preceded by suspicious execution.

Mitigation priorities

  • Start with Windows endpoint visibility: ensure process, script, file, and network telemetry is collected and retained for investigation.
  • Reduce risky script execution paths through administrative controls, least privilege, and review of PowerShell, WMI, cmd, VB, AutoHotKey, and AutoIT usage.
  • Strengthen email and file-handling controls where masqueraded or double-extension files could reach users, while recognizing the supplied object does not specify a delivery method.
  • Harden identity and local administration: monitor and restrict local/domain group changes and privileged account use.
  • Improve DNS and egress governance so C2 and exfiltration over allowed channels are observable and controllable.
Additional notes and limits

DarkGate is a Windows malware object in ATT&CK S1111. MITRE describes it as first emerging in 2018, evolving into an initial access and data gathering tool, and being associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. The strongest defensive value comes from mapping the related techniques into testable detection and response use cases rather than treating DarkGate as a single static malware signature.

MITRE provides no official detection text, no aliases, no object-level tactics, and only Windows as the platform for this object. The relationship list supplies behavior context but does not prove local exposure, active intrusion, or detection coverage. Local telemetry, incident evidence, and approved threat intelligence are required to determine relevance in a specific environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

58 rows
DomainIDNameRelationship / procedure
EnterpriseT1082System Information Discovery

DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount.[1][3]

EnterpriseT1569.002Service ExecutionSub-technique

DarkGate tries to elevate privileges to SYSTEM using PsExec to locally execute as a service, such as cmd /c c:\temp\PsExec.exe -accepteula -j -d -s [Target Binary].[2]

EnterpriseT1071.004DNSSub-technique

DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. [1]

EnterpriseT1119Automated Collection

DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified.[1]

EnterpriseT1574Hijack Execution Flow

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script.[1] When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

EnterpriseT1480Execution Guardrails

DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them.[2]

EnterpriseT1548.002Bypass User Account ControlSub-technique

DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges.[1]

EnterpriseT1622Debugger Evasion

DarkGate checks the BeingDebugged flag in the PEB structure during execution to identify if the malware is being debugged.[2]

EnterpriseT1685Disable or Modify Tools

DarkGate will terminate processes associated with several security software products if identified during execution.[1]

EnterpriseT1486Data Encrypted for Impact

DarkGate can deploy follow-on ransomware payloads.[1]

EnterpriseT1566.002Spearphishing LinkSub-technique

DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files.[2] DarkGate uses applications such as Microsoft Teams for distributing links to payloads.[2]

EnterpriseT1614System Location Discovery

DarkGate queries system locale information during execution.[1] Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.[2]

EnterpriseT1680Local Storage Discovery

DarkGate uses the Delphi methods Sysutils::DiskSize and GlobalMemoryStatusEx to collect disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment.[1]

EnterpriseT1010Application Window Discovery

DarkGate will search for cryptocurrency wallets by examining application window names for specific strings.[1] DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the FindWindow API function.[1]

EnterpriseT1070.004File DeletionSub-technique

DarkGate has deleted its staging directories.[3]

EnterpriseT1036.007Double File ExtensionSub-technique

DarkGate masquerades malicious LNK files as PDF objects using the double extension .pdf.lnk.[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder.[1][3] DarkGate installation finishes with the creation of a registry Run key.[1]

EnterpriseT1041Exfiltration Over C2 Channel

DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials.[1]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation.[1] DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads.[2]

EnterpriseT1552Unsecured Credentials

DarkGate uses NirSoft tools to steal user credentials from the infected machine.[1] NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe.

EnterpriseT1005Data from Local System

DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.[3]

EnterpriseT1047Windows Management Instrumentation

DarkGate has used WMI to execute files over the network and to obtain information about the domain.[3]

EnterpriseT1027Obfuscated Files or Information

DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes.[2]

EnterpriseT1490Inhibit System Recovery

DarkGate can delete system restore points through the command cmd.exe /c vssadmin delete shadows /for=c: /all /quiet”.[1]

EnterpriseT1036.003Rename Legitimate UtilitiesSub-technique

DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\\ root directory that copies and renames the legitimate Windows curl command to this new location.[2]

EnterpriseT1059.001PowerShellSub-technique

DarkGate has used PowerShell to create a remote shell.[3]

EnterpriseT1496.001Compute HijackingSub-technique

DarkGate can deploy follow-on cryptocurrency mining payloads.[1]

EnterpriseT1136.001Local AccountSub-technique

DarkGate creates a local user account, SafeMode, via net user commands.[1]

EnterpriseT1056.001KeyloggingSub-technique

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.[1][3]

EnterpriseT1059.010AutoHotKey & AutoITSub-technique

DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`.[1]

EnterpriseT1665Hide Infrastructure

DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services.[2]

EnterpriseT1105Ingress Tool Transfer

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server.[1] DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads.[2] DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.[3]

EnterpriseT1057Process Discovery

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.[1][3]

EnterpriseT1583.001DomainsSub-technique

DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services.[2]

EnterpriseT1555Credentials from Password Stores

DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions.[2]

EnterpriseT1083File and Directory Discovery

Some versions of DarkGate search for the hard-coded folder C:\Program Files\e Carte Bleue.[1]

EnterpriseT1106Native API

DarkGate uses the native Windows API CallWindowProc() to decode and launch encoded shellcode payloads during execution.[2] DarkGate can call kernel mode functions directly to hide the use of process hollowing methods during execution.[1] DarkGate has also used the `CreateToolhelp32Snapshot`, `GetFileAttributesA` and `CreateProcessA` functions to obtain a list of running processes, to check for security products and to execute its malware.[3]

EnterpriseT1140Deobfuscate/Decode Files or Information

DarkGate installation includes binary code stored in a file located in a hidden directory, such as shell.txt, that is decrypted then executed.[1] DarkGate uses hexadecimal-encoded shellcode payloads during installation that are called via Windows API CallWindowProc() to decode and then execute.[2]

EnterpriseT1204.002Malicious FileSub-technique

DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution.[1] DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.[2]

EnterpriseT1124System Time Discovery

DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename.[1] DarkGate queries victim system epoch time during execution.[1] DarkGate captures system time information as part of automated profiling on initial installation.[2]

EnterpriseT1518.001Security Software DiscoverySub-technique

DarkGate looks for various security products by process name using hard-coded values in the malware.[3] DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

DarkGate can be distributed through emails with malicious attachments from a spoofed email address.[1]

EnterpriseT1657Financial Theft

DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets.[1]

EnterpriseT1115Clipboard Data

DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file.[1][3]

EnterpriseT1574.001DLLSub-technique

DarkGate includes one infection vector that leverages a malicious "KeyScramblerE.DLL" library that will load during the execution of the legitimate KeyScrambler application.[2]

EnterpriseT1134.004Parent PID SpoofingSub-technique

DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer.[2]

EnterpriseT1574.007Path Interception by PATH Environment VariableSub-technique

DarkGate overrides the %windir% environment variable by setting a Registry key, HKEY_CURRENT_User\Environment\windir, to an alternate command to execute a malicious AutoIt script. This allows DarkGate to run every time the scheduled task DiskCleanup is executed as this uses the path value %windir%\system32\cleanmgr.exe for execution.[1]

EnterpriseT1539Steal Web Session Cookie

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.[3]

EnterpriseT1098.007Additional Local or Domain GroupsSub-technique

DarkGate elevates accounts created through the malware to the local administration group during execution.[1]

EnterpriseT1059.005Visual BasicSub-technique

DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim.[1]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name.[1] Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`.[5]

EnterpriseT1529System Shutdown/Reboot

DarkGate has used the `shutdown`command to shut down and/or restart the victim system.[3]

EnterpriseT1001Data Obfuscation

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.[1]

EnterpriseT1497.001System ChecksSub-technique

DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment.[1]

EnterpriseT1561.001Disk Content WipeSub-technique

DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`.[3]

EnterpriseT1036Masquerading

DarkGate can masquerade as pirated media content for initial delivery to victims.[1]

EnterpriseT1055.012Process HollowingSub-technique

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.[1][3]

EnterpriseT1059.003Windows Command ShellSub-technique

DarkGate uses a malicious Windows Batch script to run the Windows code utility to retrieve follow-on script payloads.[2] DarkGate has also used `cmd.exe` to create a remote shell.[3]

Associated objects

Groups, software, and campaigns

CampaignEnterprise

C0037: Water Curupira Pikabot Distribution

Pikabot was distributed in Water Curupira Pikabot Distribution throughout 2023 by an entity linked to BlackBasta ransomware deployment via email attachments. This activity followed the take-down of QakBot, with several technical overlaps and similarities with QakBot, indicating a possible connection. The identified activity led to the deployment of tools such as Cobalt Strike, while coinciding with campaigns delivering DarkGate and IcedID en route to ransomware deployment.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
a29cd382d9c4a810...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundlea29cd382d9c4…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  2. [2]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  3. [3]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  4. [4]
    TrendMicro Pikabot 2024

    Shinji Robert Arasawa, Joshua Aquino, Charles Steven Derion, Juhn Emmanuel Atanque, Francisrey Joshua Castillo, John Carlo Marquez, Henry Salcedo, John Rainier Navato, Arianne Dela Cruz, Raymart Yambot & Ian Kenefick. (2024, January 9). Black Basta-Affiliated Water Curupira’s Pikabot Spam Campaign. Retrieved July 17, 2024.

    Open source URL
  5. [5]
    gbhackers Darkgate Malware 2024

    Divya. (2024, April 30). Darkgate Malware Leveraging Autohotkey Following Teams. Retrieved November 22, 2024.

    Open source URL
  6. [6]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  7. [7]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  8. [8]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  9. [9]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  10. [10]
    mitre-attackS1111
    Open source URL
  11. [11]
    mitre-attackS1111
    Open source URL
  12. [12]
    mitre-attackS1111
    Open source URL
  13. [13]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  14. [14]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  15. [15]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  16. [16]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  17. [17]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  18. [18]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  19. [19]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  20. [20]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  21. [21]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  22. [22]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  23. [23]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  24. [24]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  25. [25]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  26. [26]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  27. [27]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  28. [28]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  29. [29]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  30. [30]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  31. [31]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  32. [32]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  33. [33]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  34. [34]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  35. [35]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  36. [36]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  37. [37]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  38. [38]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  39. [39]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  40. [40]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  41. [41]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  42. [42]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  43. [43]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  44. [44]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  45. [45]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  46. [46]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  47. [47]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  48. [48]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  49. [49]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  50. [50]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  51. [51]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  52. [52]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  53. [53]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  54. [54]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  55. [55]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  56. [56]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  57. [57]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  58. [58]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  59. [59]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  60. [60]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  61. [61]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  62. [62]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  63. [63]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  64. [64]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  65. [65]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  66. [66]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  67. [67]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  68. [68]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  69. [69]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  70. [70]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  71. [71]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  72. [72]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  73. [73]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  74. [74]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  75. [75]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  76. [76]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  77. [77]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  78. [78]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  79. [79]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  80. [80]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  81. [81]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  82. [82]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  83. [83]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  84. [84]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  85. [85]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  86. [86]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  87. [87]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  88. [88]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  89. [89]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  90. [90]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  91. [91]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  92. [92]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  93. [93]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  94. [94]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  95. [95]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  96. [96]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  97. [97]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  98. [98]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  99. [99]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  100. [100]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  101. [101]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  102. [102]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  103. [103]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  104. [104]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  105. [105]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  106. [106]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  107. [107]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  108. [108]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  109. [109]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  110. [110]
    TrendMicro Pikabot 2024

    Shinji Robert Arasawa, Joshua Aquino, Charles Steven Derion, Juhn Emmanuel Atanque, Francisrey Joshua Castillo, John Carlo Marquez, Henry Salcedo, John Rainier Navato, Arianne Dela Cruz, Raymart Yambot & Ian Kenefick. (2024, January 9). Black Basta-Affiliated Water Curupira’s Pikabot Spam Campaign. Retrieved July 17, 2024.

    Open source URL
  111. [111]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  112. [112]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  113. [113]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  114. [114]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  115. [115]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  116. [116]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  117. [117]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  118. [118]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  119. [119]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  120. [120]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  121. [121]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  122. [122]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  123. [123]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  124. [124]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  125. [125]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  126. [126]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  127. [127]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  128. [128]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  129. [129]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  130. [130]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  131. [131]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  132. [132]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  133. [133]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  134. [134]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  135. [135]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  136. [136]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  137. [137]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  138. [138]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  139. [139]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  140. [140]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  141. [141]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  142. [142]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  143. [143]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  144. [144]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  145. [145]
    gbhackers Darkgate Malware 2024

    Divya. (2024, April 30). Darkgate Malware Leveraging Autohotkey Following Teams. Retrieved November 22, 2024.

    Open source URL
  146. [146]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  147. [147]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  148. [148]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  149. [149]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  150. [150]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  151. [151]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  152. [152]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  153. [153]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  154. [154]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  155. [155]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  156. [156]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.