DarkGate Malware opens RaaS For Financially Motivated Hackers

Following the FBI’s shutdown of Qakbot infrastructure in August 2023, security analysts at EclecticIQ observed a surge in the use of the DarkGate loader.

EclecticIQ believes DarkGate is primarily in the hands of financially motivated groups like TA577 and Ducktail and RaaS operators like BianLian and Black Basta.

These groups focus on European and American financial institutions, employing double extortion ransomware attacks to squeeze maximum profit

Overview of DarkGate version 5 activity

They exploit legitimate services like Google’s DoubleClick advertising network and cloud storage to trick victims into downloading the malware.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks .

DarkGate offered on Forums

On June 16, 2023, a cybercriminal known as RastaFarEye advertised a dangerous service on online forums: DarkGate Malware-as-a-Service (MaaS). 

This service gave hackers tools to control victims’ devices and steal their data remotely.

Persona RastaFarEye advertising DarkGate on a cybercrime forum.

Phishing Scam

Security researchers at EclecticIQ believe cybercriminals behind DarkGate malware primarily target financial institutions. 

One example involves a phishing attempt against Bank Deutsches Kraftfahrzeuggewerbe (BDK), the second-largest independent bank in Germany’s automotive sector.

The attackers sent an email with a malicious PDF attachment using an automotive-themed lure, likely to exploit BDK’s industry focus.

Clicking the “Open” button in the PDF redirected victims to a phishing website designed to download DarkGate.

The phishing site delivered the malware disguised within a ZIP compressed file, a common tactic to bypass security measures.

Automotive-themed lure in PDF document

Recommendations Suggested

Look for activity where wscript.exe or cscript.exe are used to run .vbs files, especially from temporary folders. 

Tools like the SIGMA rule “Suspicious Script Execution from Temp Folder” or an Elasticsearch KQL query can help detect this.

Monitor network traffic for unusual patterns, such as redirects to strange domains like “adclick.g.doubleclick.net” with suspicious parameters or downloads of .CAB files.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…

3 hours ago

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…

2 days ago

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…

2 days ago

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…

2 days ago

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…

2 days ago

Beware! Fake Unpaid Tolls Messages Used in Phishing Attack to Steal Login Credentials

A surge in phishing text messages claiming unpaid tolls has been linked to a massive…

2 days ago