Tag

Darkgate Malware

All articles tagged with #darkgate malware

cybersecurity1 year ago

"DarkGate Malware Exploits Unpatched Windows Flaw in Zero-Day Attack"

A DarkGate malware campaign exploited a recently patched Microsoft Windows flaw in a zero-day attack, using bogus software installers and Google DoubleClick Digital Marketing open redirects to lead victims to compromised sites hosting the vulnerability. The attack chain involved phishing emails with PDF attachments, open redirects, and fake software installers to deliver the DarkGate malware. Additionally, counterfeit installers for popular software like Adobe Reader and Notion are being used to distribute information stealers, while new stealer malware families like Planet Stealer and Tweaks are being exploited through platforms like YouTube and Discord. Malvertising and social engineering campaigns are also being used to disseminate a wide range of stealer and remote access trojans.

cybersecurity1 year ago

"DarkGate Malware Spreading Through Microsoft Teams Group Chats"

Cybercriminals are exploiting Microsoft Teams group chat requests to distribute DarkGate malware, with over 1,000 malicious invites sent using compromised accounts. Once victims accept the chat request, they are tricked into downloading a file containing the malware. This attack underscores the importance of securing Microsoft Teams by disabling External Access and training users to recognize and avoid phishing attempts. The surge in DarkGate infections follows the disruption of the Qakbot botnet, with cybercriminals increasingly turning to DarkGate as their preferred method of gaining initial access to corporate networks.

cybersecurity2 years ago

Skype accounts compromised, DarkGate malware spreads rapidly

DarkGate malware has been spreading through compromised Skype accounts, with attackers using VBA loader script attachments to infect targets. The malware operators have also attempted to push their payload through Microsoft Teams. DarkGate has become increasingly popular among cybercriminals for initial access into corporate networks, offering a range of features and posing various threats, including ransomware and cryptomining. This surge in DarkGate activity highlights the growing influence of this malware-as-a-service operation and the determination of threat actors to adapt their tactics despite disruptions.