Recent crimeware activity shows DarkGate, Emotet, and LokiBot continuing to rely on layered infection chains, phishing lures, and in-memory execution to evade detection and deliver malware. DarkGate has been distributed through a multi-stage sequence involving a VBS downloader, AutoIT components, shellcode, and a final loader that decrypts and runs its payload in memory. Emotet has likewise remained active after its earlier disruption, using malicious OneNote attachments and VBScript downloaders to retrieve a DLL that decrypts shellcode and launches the final payload while attempting to avoid analysis.
LokiBot activity has also persisted through phishing campaigns, including operations targeting cargo shipping companies with fake macro-themed lures and exploits for CVE-2017-0199 and CVE-2017-11882 to install the infostealer. U.S. government reporting has previously linked LokiBot to sustained credential theft, keylogging, password store extraction, process hollowing, HTTP-based command-and-control, and occasional backdoor functionality for follow-on payloads, underscoring that older Office vulnerabilities and social-engineering delivery remain effective for commodity malware operators.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
A well-known malware developer advertised DarkGate in June 2023 on a popular dark web forum. The listing promoted capabilities including Hidden VNC, Windows Defender exclusion, reverse proxy, file management, and credential-related theft features.
The references state that Emotet was taken down in 2021 before later resurfacing. This establishes the disruption point preceding the malware's renewed activity.
CISA, with contributions from MS-ISAC, released advisory AA20-266A covering LokiBot activity, behaviors, ATT&CK mappings, and detection guidance including a Snort signature. The alert documented the malware's credential theft, keylogging, backdoor, and HTTP C2 capabilities.
CISA reported a notable increase in LokiBot use by malicious cyber actors since July 2020. The agency also said its EINSTEIN intrusion detection system saw persistent LokiBot activity on U.S. federal civilian executive branch networks.
CISA cited Trend Micro reporting from February 2018 that attackers exploited CVE-2017-11882 to deliver LokiBot using the Windows Installer service. Kaspersky also described a later LokiBot chain using CVE-2017-11882.
The DarkGate developer claimed the loader project had been under development since 2017, with more than 20,000 hours invested. This marks the earliest stated origin point for DarkGate in the references.
Kaspersky described LokiBot as an infostealer that first surfaced in 2016 and remains active. CISA also cited reporting from February 2016 on LokiBot Android trojan activity.
Microsoft published CVE-2017-0199 for a Microsoft Office/WordPad remote code execution vulnerability. Kaspersky later described LokiBot campaigns exploiting this flaw in their delivery chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcecisa.gov
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.