Researchers detailed multiple DarkGate infection chains that began with phishing lures themed as invoices or DocuSign documents and pushed victims toward malicious CAB and MSI installers. In one case, a wrapped DoubleClick ad URL delivered an MSI signed with a valid certificate issued to “Inoellact EloubantTech Optimization Information Co., Ltd.”, helping the malware evade reputation checks. The installer unpacked a cabinet containing legitimate signed binaries alongside tampered DLLs, enabling DLL sideloading and staged decryption before launching the next payload.
Analysis showed DarkGate using a layered loader architecture built around Delphi components and AutoIt scripts to reconstruct shellcode in memory and execute the final malware. One chain used a legitimate Apple binary with a modified CoreFoundation.dll and an encrypted sqlite3.dll; another abused windbg.exe in a similar sideloading flow. The recovered payload was the DarkGate agent, a malware-as-a-service loader capable of remote access and follow-on malware delivery, and one sample communicated with prodomainnameeforappru[.]com (46.21.157.142) over port 443.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Netskope said DarkGate was first reported by enSilo, now Fortinet, in 2018. This establishes the earliest dated reference point in the story.
Runtime analysis in the SANS ISC diary identified the final payload as the DarkGate agent, mapped into a spawned VBC.exe process. The malware beaconed to prodomainnameeforappru[.]com, which resolved to 46.21.157.142 on port 443.
A SANS ISC guest diary analyzed a DarkGate infection chain starting from a phishing PDF that used a fake load error and an Open button to fetch a malicious MSI through a wrapped DoubleClick ad URL. The MSI was signed with a valid certificate and unpacked files used for DLL sideloading, decryption, and staged execution.
Netskope assessed its samples as part of a new DarkGate version that used a loading approach resembling Cobalt Strike Beacon’s default shellcode stub. It also published detections, IOCs, scripts, and YARA rules for the campaign.
Netskope Threat Labs analyzed a DarkGate campaign that began with a fake invoice email and DocuSign-themed PDF lure, leading to a CAB file, then an MSI, and a multi-stage loading chain. The campaign used DLL sideloading with windbg.exe, Delphi loaders, and an AutoIt stage to execute the final DarkGate payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
dshield.org
Open sourcenetskope.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.