DarkGate Malware Abuses AutoIT Scripting For Payload Obfustication

DarkGate is a type of malware that employs Auto-It compiled loaders that cause a considerable threat because of its advanced evasion strategies and persistence within compromised systems.

By using obfuscated AutoIt scripting and multi-stage payloads, the malware makes it more difficult to identify using conventional signature-based techniques.

Meticulous detection and analysis are necessary due to their capacity to obtain command and control communications and exfiltrate sensitive data.

The scripting language AutoIt was created specifically for automating Windows GUI and general scripting tasks. It has been used for malicious purposes throughout history, including AutoIt-compiled malware dating back to 2008.

“Malware creators have exploited the versatility of AutoIT in a variety of ways, such as using obfuscated scripts for payload decryption, utilizing legitimate tools like BaSupportVNC, and even creating worms capable of spreading through removable media and Windows shares”, said Splunk researchers.

Document
Free Webinar

Fastrack Compliance: The Path to ZERO-Vulnerability

Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.

Insights of DarkGate Malware and Its Use of AutoIt

Researchers discovered several campaigns using a loader intended for launching DarkGate on hacked systems. An instance of this would be the discovery of malicious PDF files that serve as carriers and cause a malicious CAB file to be downloaded. 

This CAB file, in turn, downloads a.MSI file containing and loading the DarkGate malware. This file appears to load a series of files, including two.BIN files, a DLL module, and the legitimate wndbg.exe, all of which are necessary for DarkGate to execute.

Malicious MSI Infection Flow

In a different variation, it adds another .CAB installer to the targeted host’s installation process, expanding its infection strategy. This enhanced strategy highlights threat actors’ ongoing attempts to avoid detection by highlighting the intricacy and sophistication of the infection mechanism they have chosen.

Four.png files are utilized solely as dummies or decoys to hide or mislead the observer from the important parts of the DarkGate operation.

.CAB Extracted Files

“Within the .CAB file, a collection of files has been identified. Among these files, the pivotal components driving the initiation of DarkGate malware include windbg.exe, dbgeng.dll, data.bin, and data2.bin”, researchers said.

The subsequent stage of this malicious installation of the .CAB file entails the use of windbg.exe to execute a specifically designed dbgeng.dll via DLL side-loading techniques.

Data2.bin contains two encoded files, separated by the ‘splitres’ string. The first file to be decoded from the base64 process is a legitimate Autoit3.exe, which is used to run the second file, which is a script.au3 AutoIt script that has been constructed. 

The final loader encompasses both a shellcode and a .exe file designed to decrypt the DarkGate malware.

Hence, maintaining a strong defense against DarkGate’s shifting techniques requires constant monitoring in addition to updated defense systems.

Try Kelltron’s cost-effective penetration testing services to evaluate digital systems security. available.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Threat Actors Selling Nunu Stealer On Hacker Forums

A new malware variant called Nunu Stealer is making headlines after being advertised on underground hacker forums…

22 hours ago

Siemens UMC Vulnerability Allows Arbitrary Remote Code Execution

A critical vulnerability has been identified in Siemens' User Management Component (UMC), which could allow…

23 hours ago

Foxit PDF Editor Vulnerabilities Allows Remote Code Execution

Foxit Software has issued critical security updates for its widely used PDF solutions, Foxit PDF…

1 day ago

Windows 11 Privilege Escalation Vulnerability Lets Attackers Execute Code to Gain Access

Microsoft has swiftly addressed a critical security vulnerability affecting Windows 11 (version 23H2), which could…

1 day ago

NetWalker Ransomware Operator Sentenced to 20 Years in Prison

A Romanian man has been sentenced to 20 years in prison for his involvement in…

1 day ago

CISA Warns of BeyondTrust Privileged Remote Access Exploited in Wild

 The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm over a critical vulnerability…

1 day ago