DarkGate-Malware ersetzt AutoIt durch AutoHotkey in neuesten Cyber-Angriffen

Teilen:

Cyber attacks involving the DarkGate malware-as-a-service (MaaS) operation have shifted away from AutoIt scripts to an AutoHotkey mechanism to deliver the last stages, underscoring continued efforts on the part of the threat actors to continuously stay ahead of the detection curve.

The updates have been observed in version 6 of DarkGate released in March 2024 by its developer RastaFarEye, who has been selling the program on a subscription basis to as many as 30 customers. The malware has been active since at least 2018.

A fully-featured remote access trojan (RAT), DarkGate is equipped with command-and-control (C2) and rootkit capabilities, and incorporates various modules for credential theft, keylogging, screen capturing, and remote desktop.

“DarkGate campaigns tend to adapt really fast, modifying different components to try to stay off security solutions,” Trellix security researcher Ernesto Fernández Provecho said in a Monday analysis. “This is the first time we find DarkGate using AutoHotKey, a not so common scripting interpreter, to launch DarkGate.”

It’s worth noting that DarkGate’s switch to AutoHotKey was first documented by McAfee Labs in late April 2024, with attack chains leveraging security flaws such as CVE-2023-36025 and CVE-2024-21412 to bypass Microsoft Defender SmartScreen protections using a Microsoft Excel or an HTML attachment in phishing emails.

Alternate methods have been found to leverage Excel files with embedded macros as a conduit to execute a Visual Basic Script file that’s responsible for invoking PowerShell commands to ultimately launch an AutoHotKey script, which, in turn, retrieves and decodes the DarkGate payload from a text file.

The latest version of DarkGate packs in substantial upgrades to its configuration, evasion techniques, and the list of supported commands, which now includes audio recording, mouse control, and keyboard management features.

“Version 6 not only includes new commands, but also lacks some of them from previous versions, like the privilege escalation, the cryptomining, or the hVNC (Hidden Virtual Network Computing) ones,” Fernández Provecho said, adding it may be an effort to cut out features that could enable detection.

“Moreover, since DarkGate is sold to a small group of people, it is also possible that the customers were not interested in those features, forcing RastaFarEye to remove them.”

The disclosure comes as cyber criminals have been found abusing Docusign by selling legitimate-looking customizable phishing templates on underground forums, turning the service into a fertile ground for phishers looking to steal credentials for phishing and business email compromise (BEC) scams.

“These fraudulent emails, meticulously designed to mimic legitimate document signing requests, lure unsuspecting recipients into clicking malicious links or divulging sensitive information,” Abnormal Security said.

AutoHotKey-based DarkGate Campaigns Target the U.S., Europe, and Asia#

Cisco Talos, in a new report published on June 5, 2024, said it uncovered DarkGate malware campaigns using AutoHotKey scripts as part of phishing attacks primarily targeting healthcare technology, telecommunication, and fintech sectors spanning the U.S., Europe, and Asia.

“The infection process begins when the malicious Excel document is opened,” security researcher Kalpesh Mantri said. “These files were specially crafted to utilize a technique, called ‘Remote Template Injection,’ to trigger the automatic download and execution of malicious contents hosted on a remote server.”

 

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:14 am, Juli 13, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
overcast clouds
Luftfeuchtigkeit: 86 %
Druck: 1013 mb
Wind: 5 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 18°°C 0 mm 0% 6 mph 77 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 72 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 0.94 mm 94% 15 mph 79 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
15° | 26°°C 0.4 mm 40% 13 mph 90 % 1016 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
19° | 25°°C 0 mm 0% 7 mph 61 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 23°°C 0 mm 0% 4 mph 77 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
25° | 28°°C 0 mm 0% 3 mph 52 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 0 mph 28 % 1010 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 6 mph 61 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 72 % 1011 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,876.28
-0.02%
Ethereum(ETH)
€2,532.19
-0.11%
XRP(XRP)
€2.39
0.27%
Fesseln(USDT)
€0.86
-0.01%
Solana(SOL)
€138.39
-1.09%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.170079
-1.72%
Shiba Inu(SHIB)
€0.000011
-1.20%
Pepe(PEPE)
€0.000010
-2.10%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen