DarkGate is a malware-as-a-service and loader ecosystem active since at least 2018 and associated with the developer known as RastaFarEye, while operational campaigns are conducted by affiliates. Following the 2023 disruption of QakBot, DarkGate rose sharply in prevalence and became a prominent phishing-delivered payload used to feed broader criminal intrusion and ransomware ecosystems. It is best characterized as a commodity loader and post-compromise platform rather than a named state-backed intrusion set. DarkGate has been distributed through phishing and malicious installer campaigns, including MSI-based delivery chains that abused CVE-2024-21412 to bypass Microsoft Windows SmartScreen protections. It has also been observed in heavily layered loader chains using self-extracting archives, obfuscated batch scripts, AutoIt-based stages, RC4 decryption, LZNT1 decompression, and in-memory execution of the core payload. Some campaigns co-delivered additional stealers such as LummaStealer, indicating an emphasis on credential harvesting alongside loader deployment. Technically, DarkGate supports extensive defense evasion and execution tradecraft. Reported techniques include APC-based execution, including self-injection via NtTestAlert and Early Bird APC-style process injection, as well as process hollowing into legitimate Windows processes. Samples have performed anti-analysis and anti-sandbox checks, security-product awareness, and NTDLL unhooking by restoring a clean in-memory code section from disk. DarkGate has also been observed deleting system restore points and shadow copies to inhibit recovery. The malware’s functional scope spans initial payload execution, persistence, credential theft, and post-exploitation support. Its role in criminal operations is to establish footholds, evade defenses, and enable follow-on activity by affiliates, including ransomware deployment. DarkGate is widely discussed alongside other commodity loaders such as Pikabot and as part of the post-QakBot loader landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/example of another malicious MSI campaign.
A widely used phishing payload whose loader performs local self-injection using APCs and NtTestAlert to execute queued APCs within the same process for stealth.
Malware-as-a-Service operation delivering DarkGate v6 in a five-layer infection chain for credential theft and command-and-control activity. The campaign analyzed used process hollowing, AutoIt3 obfuscation, RC4+LZNT1 payload decryption, anti-analysis checks, and co-delivery with LummaStealer.
Commodity loader linked in the content to Safe VPN S.A. infrastructure and ransomware enablement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.