DarkGate is a malware-as-a-service threat group associated with the DarkGate malware family. The group has been observed developing and distributing updated versions of the malware, including a version 4 release in 2023. DarkGate is known for post-compromise tradecraft centered on process injection for stealth and execution within legitimate processes. Reported techniques include portable executable injection and APC injection, enabling code execution inside other processes to evade detection and blend malicious activity with normal system behavior. The malware has also been described as having rootkit capabilities that support code or binary injection into different processes. High-confidence reporting links the group to defense evasion, persistence, and privilege-escalation behavior through these injection methods. Available information supports characterization of DarkGate primarily as a malware service operation rather than a clearly attributed nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.