Meta tags:
Headings (most frequently used words):
darkgate, techniques, used, campaigns, references, enterprise, layer,
Text of the page (most frequently used words):
#darkgate (88), the (59), enterprise (55), and (44), for (22), execution (20), command (20), system (18), uses (15), malware (14), all (13), process (13), 001 (12), during (12), such (12), att (11), files (11), windows (11), payloads (11), malicious (11), file (11), from (11), software (10), data (10), has (10), can (10), exe (10), with (10), control (10), 2024 (9), information (9), user (9), victim (9), installation (9), discovery (9), will (9), cryptocurrency (8), its (8), that (8), directory (8), techniques (7), used (7), execute (7), initial (7), credentials (7), services (7), security (7), detection (6), retrieved (6), name (6), tools (6), hard (6), coded (6), associated (6), encrypted (6), script (6), legitimate (6), local (6), account (6), are (5), use (5), ics (5), mobile (5), none (5), domains (5), ransomware (5), environment (5), checks (5), through (5), via (5), using (5), version (5), follow (5), registry (5), autoit (5), includes (5), shell (5), mitre (4), objects (4), service (4), new (4), mining (4), domain (4), machine (4), content (4), phishing (4), links (4), 002 (4), nirsoft (4), steal (4), executed (4), hollowing (4), time (4), location (4), various (4), products (4), thread (4), identified (4), api (4), hide (4), lnk (4), this (4), xml (4), key (4), run (4), application (4), hidden (4), scripting (4), interpreter (4), 2026 (3), resources (3), campaigns (3), groups (3), cti (3), defenses (3), water (3), curupira (3), pikabot (3), campaign (3), following (3), november (3), february (3), distribution (3), queries (3), identify (3), executing (3), infection (3), masquerade (3), pirated (3), media (3), code (3), distributed (3), created (3), log (3), keylogging (3), clipboard (3), related (3), part (3), cmd (3), versions (3), type (3), present (3), web (3), anti (3), deploy (3), evade (3), running (3), processes (3), also (3), encoded (3), decode (3), 007 (3), batch (3), named (3), masquerading (3), disk (3), commands (3), server (3), retrieve (3), appdata (3), 004 (3), path (3), windir (3), wallets (3), search (3), folder (3), stored (3), create (3), window (3), corporation (2), cookie (2), reference (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), joshua (2), john (2), black (2), basta (2), autohotkey (2), teams (2), december (2), drops (2), custom (2), 2018 (2), references (2), description (2), over (2), network (2), obtain (2), about (2), management (2), infected (2), sandbox (2), virtualized (2), evasion (2), requiring (2), interaction (2), vbs (2), msi (2), vbc (2), creates (2), capturing (2), captures (2), automated (2), shutdown (2), privileges (2), psexec (2), binary (2), locale (2), later (2), after (2), values (2), virus (2), hijacking (2), leverages (2), into (2), emails (2), microsoft (2), spearphishing (2), string (2), input (2), value (2), based (2), native (2), shellcode (2), call (2), functions (2), methods (2), callwindowproc (2), pdf (2), double (2), extension (2), curl (2), 003 (2), delphi (2), memory (2), capture (2), them (2), predefined (2), delete (2), recovery (2), traffic (2), scripts (2), stolen (2), filezilla (2), recentservers (2), sitemanager (2), tool (2), deleted (2), directories (2), variable (2), task (2), system32 (2), dll (2), when (2), modified (2), open (2), akamai (2), cdn (2), amazon (2), infrastructure (2), several (2), attrib (2), theft (2), some (2), hosting (2), mozilla (2), wipe (2), then (2), actions (2), password (2), remote (2), powershell (2), startup (2), first (2), dns (2), layer (2), manipulation (2), parent (2), pid (2), spoofing (2), access (2), bypass (2), s1111 (2), author (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, shinji, robert, arasawa, aquino, charles, steven, derion, juhn, emmanuel, atanque, francisrey, castillo, carlo, marquez, henry, salcedo, rainier, navato, arianne, dela, cruz, raymart, yambot, ian, kenefick, january, affiliated, spam, july, divya, april, leveraging, mcgraw, zbot, ernesto, fernández, provecho, pham, duy, phuc, ciana, driscoll, vinoo, thomas, 2023, continued, evolution, adi, zeligson, rotem, kerner, enter, activity, included, route, c0037, wmi, instrumentation, t1047, virtualization, t1497, t1204, newly, instance, regasm, unsecured, t1552, host, current, date, filename, epoch, profiling, t1124, shut, down, restart, reboot, t1529, tries, elevate, locally, temp, accepteula, target, t1569, query, determine, russian, speaking, countries, getsystemdefaultlcid, t1614, gather, display, adapter, operating, processor, ram, amount, t1082, attempts, opera, cookies, terminating, session, t1539, looks, not, trend, micro, runtime, presence, kaspersky, initiate, certain, recreate, any, determines, they, were, removed, t1518, compute, resource, t1496, decrypting, injecting, injection, 012, t1055, performs, including, looking, t1057, containing, distribute, applications, distributing, link, attachments, spoofed, email, address, attachment, t1566, bin, decrypts, base64, encoding, schemas, variations, obfuscate, 013, seed, along, hardware, identifier, text, generate, unique, internal, mutex, static, mutexes, obfuscated, t1027, launch, kernel, mode, directly, list, check, createprocessa, getfileattributesa, createtoolhelp32snapshot, t1106, masquerades, executes, creases, randomly, root, copies, renames, rename, utilities, delivery, victims, t1036, collect, size, physical, analysis, globalmemorystatusex, sysutils, disksize, storage, t1680, spawn, keyboard, events, write, t1056, restore, points, vssadmin, shadows, quiet, inhibit, t1490, retrieves, ingress, transfer, t1105, staging, deletion, indicator, removal, t1070, overrides, setting, alternate, allows, every, scheduled, cleanmgr, diskcleanup, hkey_current_user, interception, one, vector, keyscramblere, library, load, keyscrambler, edits, eventvwr, console, mmc, which, turn, hkcu, classes, mscfile, hijack, flow, t1574, t1665, involves, dropping, additionally, rjtu, artifacts, t1564, capable, financial, t1657, program, carte, bleue, t1083, existing, channels, captured, wallet, exfiltration, channel, t1041, per, archives, zip, sharepoint, prevent, other, entities, retrieving, guardrails, t1480, del, users, roaming, firefox, t1561, terminate, disable, modify, t1685, located, decrypted, hexadecimal, called, txt, deobfuscate, t1140, flag, peb, structure, being, debugged, beingdebugged, debugger, t1622, obfuscation, t1001, t1005, impact, t1486, netpass, rdp, stores, t1555, net, safemode, t1136, dropped, phases, test, au3, 010, mechanisms, include, launches, vbscript, visual, basic, 005, utility, t1059, starts, logs, t1115, creating, shortcut, itself, object, bill, finishes, creation, keys, boot, logon, autostart, t1547, searches, notifies, collection, t1119, examining, names, specific, strings, extracts, collected, identifying, function, findwindow, t1010, cloak, records, avoid, reputation, protocol, t1071, chosen, acquire, t1583, elevates, accounts, administration, group, additional, t1098, relies, rootkit, like, functionality, manager, explorer, token, t1134, two, distinct, uac, escalate, abuse, elevation, mechanism, t1548, view, download, navigator, layers, live, permalink, may, last, serhii, melnyk, trustwave, spiderlabs, phyo, paing, htun, chilai, secure, ltd, contributors, platforms, emerged, evolved, gathering, criminal, cyber, operations, written, credential, cryptomining, cryptotheft, pre, increased, significantly, starting, 2022, under, active, development, who, provides, offering, home, join, october, mclean, hotel, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, get, started, detections,
Text of the page (random words):
erprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software darkgate darkgate darkgate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations written in delphi and named darkgate by its author darkgate is associated with credential theft cryptomining cryptotheft and pre ransomware actions 1 darkgate use increased significantly starting in 2022 and is under active development by its author who provides it as a malware as a service offering 2 id s1111 ⓘ type malware ⓘ platforms windows contributors serhii melnyk trustwave spiderlabs phyo paing htun chilai i secure co ltd version 1 1 created 09 february 2024 last modified 12 may 2026 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1548 002 abuse elevation control mechanism bypass user account control darkgate uses two distinct user account control uac bypass techniques to escalate privileges 1 enterprise t1134 004 access token manipulation parent pid spoofing darkgate relies on parent pid spoofing as part of its rootkit like functionality to evade detection via task manager or process explorer 2 enterprise t1098 007 account manipulation additional local or domain groups darkgate elevates accounts created through the malware to the local administration group during execution 1 enterprise t1583 001 acquire infrastructure domains darkgate command and control includes hard coded domains in the malware chosen to masquerade as legitimate services such as akamai cdn or amazon web services 2 enterprise t1071 004 application layer protocol dns darkgate can cloak command and control traffic in dns records from legitimate services to avoid reputation based detection techniques 1 enterprise t1010 application window discovery darkgate will search for cryptocurrency wallets by examining application window names for specific strings 1 darkgate extracts information collected via nirsoft tools from the hosting process s memory by first identifying the window through the findwindow api function 1 enterprise t1119 automated collection darkgate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified 1 enterprise t1547 001 boot or logon autostart execution registry run keys startup folder darkgate installation includes autoit script execution creating a shortcut to itself as an lnk object such as bill lnk in the victim startup folder 1 3 darkgate installation finishes with the creation of a registry run key 1 enterprise t1115 clipboard data darkgate starts a thread on execution that captures clipboard data and logs it to a predefined log file 1 3 enterprise t1059 001 command and scripting interpreter powershell darkgate has used powershell to create a remote shell 3 003 command and scripting interpreter windows command shell darkgate uses a malicious windows batch script to run the windows code utility to retrieve follow on script payloads 2 darkgate has also used cmd exe to create a remote shell 3 005 command and scripting interpreter visual basic darkgate initial infection mechanisms include masquerading as pirated media that launches malicious vbscript on the victim 1 010 command and scripting interpreter autohotkey autoit darkgate uses autoit scripts dropped to a hidden directory during initial installation phases such as test au3 1 enterprise t1136 001 create account local account darkgate creates a local user account safemode via net user commands 1 enterprise t1555 credentials from password stores darkgate use nirsoft network password recovery or netpass tools to steal stored rdp credentials in some malware versions 2 enterprise t1486 data encrypted for impact darkgate can deploy follow on ransomware payloads 1 enterprise t1005 data from local system darkgate has stolen sitemanager xml and recentservers xml from appdata filezilla if present 3 enterprise t1001 data obfuscation darkgate will retrieved encrypted commands from its command and control server for follow on actions such as cryptocurrency mining 1 enterprise t1622 debugger evasion darkgate checks the beingdebugged flag in the peb structure during execution to identify if the malware is being debugged 2 enterprise t1140 deobfuscate decode files or information darkgate installation includes binary code stored in a file located in a hidden directory such as shell txt that is decrypted then executed 1 darkgate uses hexadecimal encoded shellcode payloads during installation that are called via windows api callwindowproc to decode and then execute 2 enterprise t1685 disable or modify tools darkgate will terminate processes associated with several security software products if identified during execution 1 enterprise t1561 001 disk wipe disk content wipe darkgate has deleted all files in the mozilla directory using the following command c del q f s c users user appdata roaming mozilla firefox 3 enterprise t1480 execution guardrails darkgate uses per victim links for hosting malicious archives such as zip files in services such as sharepoint to prevent other entities from retrieving them 2 enterprise t1041 exfiltration over c2 channel darkgate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials 1 enterprise t1083 file and directory discovery some versions of darkgate search for the hard coded folder c program files e carte bleue 1 enterprise t1657 financial theft darkgate can deploy payloads capable of capturing credentials related to cryptocurrency wallets 1 enterprise t1564 001 hide artifacts hidden files and directories darkgate initial installation involves dropping several files to a hidden directory named after the victim machine name 1 additionally darkgate uses attrib to hide a directory in the following command c windows system32 attrib exe h c rjtu 4 enterprise t1665 hide infrastructure darkgate command and control includes hard coded domains in the malware masquerading as legitimate services such as akamai cdn or amazon web services 2 enterprise t1574 hijack execution flow darkgate edits the registry key hkcu software classes mscfile shell open command to execute a malicious autoit script 1 when eventvwr exe is executed this will call the microsoft management console mmc exe which in turn references the modified registry key 001 dll darkgate includes one infection vector that leverages a malicious keyscramblere dll library that will load during the execution of the legitimate keyscrambler application 2 007 path interception by path environment variable darkgate overrides the windir environment variable by setting a registry key hkey_current_user environment windir to an alternate command to execute a malicious autoit script this allows darkgate to run every time the scheduled task diskcleanup is executed as this uses the path value windir system32 cleanmgr exe for execution 1 enterprise t1070 004 indicator removal file deletion darkgate has deleted its staging directories 3 enterprise t1105 ingress tool transfer darkgate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server 1 darkgate uses windows batch scripts executing the curl command to retrieve follow on payloads 2 darkgate has stolen sitemanager xml and recentservers xml from appdata filezilla if present 3 enterprise t1490 inhibit system recovery darkgate can delete system restore points through the command cmd exe c vssadmin delete shadows for c all quiet 1 enterprise t1056 001 input capture keylogging darkgate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file 1 3 enterprise t1680 local storage discovery darkgate uses the delphi methods sysutils disksize and globalmemorystatusex to collect disk size and physical memory as part of the malware s anti analysis checks for running in a virtualized environment 1 enterprise t1036 masquerading darkgate can masquerade as pirated media content for initial delivery to victims 1 003 rename legitimate utilities darkgate executes a windows batch script during installation that creases a randomly named directory in the c root directory that copies and renames the legitimate windows curl command to this new location 2 007 double file extension darkgate masquerades malicious lnk files as pdf objects using the double extension pdf lnk 2 enterprise t1106 native api darkgate uses the native windows api callwindowproc to decode and launch encoded shellcode payloads during execution 2 darkgate can call kernel mode functions directly to hide the use of process hollowing methods during execution 1 darkgate has also used the createtoolhelp32snapshot getfileattributesa and createprocessa functions to obtain a list of running processes to check for security products and to execute its malware 3 enterprise t1027 obfuscated files or information darkgate uses a hard coded string as a seed along with the victim machine hardware identifier and input text to generate a unique string used as an internal mutex value to evade static detection based on mutexes 2 013 encrypted encoded file darkgate drops an encrypted pe file pe bin and decrypts it during installation 1 darkgate also uses custom base64 encoding schemas in later variations to obfuscate payloads 2 enterprise t1566 001 phishing spearphishing attachment darkgate can be distributed through emails with malicious attachments from a spoofed email address 1 002 phishing spearphishing link darkgate is distributed in phishing emails containing links to distribute malicious vbs or msi files 2 darkgate uses applications such as microsoft teams for distributing links to payloads 2 enterprise t1057 process discovery darkgate performs various checks for running processes including security software by looking for hard coded process name values 1 3 enterprise t1055 012 process injection process hollowing darkgate leverages process hollowing techniques to evade detection such as decrypting the content of an encrypted pe file and injecting it into the process vbc exe 1 3 enterprise t1496 001 resource hijacking compute hijacking darkgate can deploy follow on cryptocurrency mining payloads 1 enterprise t1518 001 software discovery security software discovery darkgate looks for various security products by process name using hard coded values in the malware 3 darkgate will not execute its keylogging thread if a process name associated with trend micro anti virus is identified or if runtime checks identify the presence of kaspersky anti virus darkgate will initiate a new thread if certain security products are identified on the victim and recreate any malicious files associated with it if it determines they were removed by security software in a new system location 1 enterprise t1539 steal web session cookie darkgate attempts to steal opera cookies if present after terminating the related process 3 enterprise t1082 system information discovery darkgate will gather various system information such as domain display adapter description operating system type and version processor type and ram amount 1 3 enterprise t1614 system location discovery darkgate queries system locale information during execution 1 later versions of darkgate query getsystemdefaultlcid for locale information to determine if the malware is executing in russian speaking countries 2 enterprise t1569 002 system services service execution darkgate tries to elevate privileges to system using psexec to locally execute as a service such as cmd c c temp psexec exe accepteula j d s target binary 2 enterprise t1529 system shutdown reboot darkgate has used the shutdown command to shut down and or restart the victim system 3 enterprise t1124 system time discovery darkgate creates a log file for capturing keylogging clipboard and related data using the victim host s current date for the filename 1 darkgate queries victim system epoch time during execution 1 darkgate captures system time information as part of automated profiling on initial installation 2 enterprise t1552 unsecured credentials darkgate uses nirsoft tools to steal user credentials from the infected machine 1 nirsoft tools are executed via process hollowing in a newly created instance of vbc exe or regasm exe enterprise t1204 002 user execution malicious file darkgate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution 1 darkgate is distributed through phishing links to vbs or msi objects requiring user interaction for execution 2 enterprise t1497 001 virtualization sandbox evasion system checks darkgate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment 1 enterprise t1047 windows management instrumentation darkgate has used wmi to execute files over the network and to obtain information about the domain 3 campaigns id name description c0037 water curupira pikabot distribution water curupira pikabot distribution activity included distribution of darkgate en route to ransomware execution 5 references adi zeligson rotem kerner 2018 november 13 enter the darkgate new cryptocurrency mining and ransomware campaign retrieved february 9 2024 ernesto fernández provecho pham duy phuc ciana driscoll vinoo thomas 2023 november 21 the continued evolution of the darkgate malware as a service retrieved february 9 2024 mcgraw t 2024 december 4 black basta ransomware campaign drops zbot darkgate and custom malware retrieved december 9 2024 divya 2024 april 30 darkgate malware leveraging autohotkey following teams retrieved november 22 2024 shinji robert arasawa joshua aquino charles steven derion juhn emmanuel atanque francisrey joshua castillo john carlo marquez henry salcedo john rainier navato arianne dela cruz raymart yambot ian kenefick 2024 january 9 black basta affiliated water curupira s pikabot spam campaign retrieved july 17 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre ...
|