home.social

#darkgate — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #darkgate, aggregated by home.social.

fetched live
  1. ⚠️ New #ClickFix malware campaign is tricking users with a fake browser “fix” prompt that leads to #DarkGate being installed via clipboard PowerShell commands. 📋

    Read: hackread.com/clickfix-attack-f

    #CyberSecurity #Malware #Windows #Scam #InfoSec

  2. ⚠️ New #ClickFix malware campaign is tricking users with a fake browser “fix” prompt that leads to #DarkGate being installed via clipboard PowerShell commands. 📋

    Read: hackread.com/clickfix-attack-f

    #CyberSecurity #Malware #Windows #Scam #InfoSec

  3. A new malicious campaign uses impersonation via Microsoft Teams voice phishing (vishing), tricking the victims into downloading AnyDesk for remote access and deploying #DarkGate malware.

    socprime.com/blog/darkgate-mal

  4. #Malware infiltrates #Pidgin messenger’s official plugin repository bleepingcomputer.com/news/secu I used to use Pidgin to communicate with friends on AIM and similar messenger apps. The malicious plugin was offered only as a binary, not open source code. Worryingly, it had valid signatures, and so did the malware it downloaded. #DarkGate #Jabber #messenger

  5. #Malware infiltrates #Pidgin messenger’s official plugin repository bleepingcomputer.com/news/secu I used to use Pidgin to communicate with friends on AIM and similar messenger apps. The malicious plugin was offered only as a binary, not open source code. Worryingly, it had valid signatures, and so did the malware it downloaded. #DarkGate #Jabber #messenger

  6. We have new intel regarding a campaign using "PasteJacking" to distribute the DarkGate malware. Nothing like end-users blindly pasting the contents of their clipboard and following malicious instructions - 🤦‍♂️ - We discuss in detail in this episode of The Security Swarm Podcast > buff.ly/3KFnK9w - #cybersecurity #darkgate #secops

  7. We have new intel regarding a campaign using "PasteJacking" to distribute the DarkGate malware. Nothing like end-users blindly pasting the contents of their clipboard and following malicious instructions - 🤦‍♂️ - We discuss in detail in this episode of The Security Swarm Podcast > buff.ly/3KFnK9w - #cybersecurity #darkgate #secops

  8. Под капотом DarkGate: разбираем ВПО-мультитул

    Исследователи кибербезопасности обнаружили вредоносное ПО, которое сочетает в себе функции загрузчика, стилера и RAT. Рассказываем, как оно было разработано, для чего используется и почему применяется в атаках на российские компании вопреки ограничению от разработчика. Читать

    habr.com/ru/companies/bizone/a

    #darkgate #впо #вредоносное_программное_обеспечение #реверс_инжиниринг #исследование_безопасности #rat #стилер #загрузчик

  9. Campagne #Malware #Italy Week 15

    👻💣🔥☠️
    #AgentTesla: Ordine
    #Formbook: Fattura
    #SpyNote #Irata: APK Bank - INPS
    #Guloader: Contratto
    #DarkGate: Documento
    #Remcos: Offerta
    #ZGRat: Booking
    #mwitaly

  10. CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign

    A recent DarkGate campaign exploited CVE-2024-21412, a Microsoft Windows SmartScreen bypass vulnerability, through phishing PDFs containing Google DoubleClick redirects that led victims to sites hosting the exploit and fake software installers to deploy the malware payload. The installers used DLL sideloading to execute the malware, which had multiple stages employing encryption and obfuscation to evade detection.

    Pulse ID: 65f3218a873a7f237e5bc3b5
    Pulse Link: otx.alienvault.com/pulse/65f32
    Pulse Author: AlienVault
    Created: 2024-03-14 16:10:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Windows #Microsoft #Google #RAT #SideLoading #DarkGate #Phishing #ZeroDay #Vulnerability #Encryption #PDF #AlienVault

  11. CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign

    A recent DarkGate campaign exploited CVE-2024-21412, a Microsoft Windows SmartScreen bypass vulnerability, through phishing PDFs containing Google DoubleClick redirects that led victims to sites hosting the exploit and fake software installers to deploy the malware payload. The installers used DLL sideloading to execute the malware, which had multiple stages employing encryption and obfuscation to evade detection.

    Pulse ID: 65f3218a873a7f237e5bc3b5
    Pulse Link: otx.alienvault.com/pulse/65f32
    Pulse Author: AlienVault
    Created: 2024-03-14 16:10:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Windows #Microsoft #Google #RAT #SideLoading #DarkGate #Phishing #ZeroDay #Vulnerability #Encryption #PDF #AlienVault

  12. Dissecting DarkGate: Modular Malware Delivery and Persistence as a Service

    This report analyzes a phishing PDF that led to the delivery of a signed MSI file containing layered stages designed to avoid detection and deliver the DarkGate malware for persistence and remote access. The analysis covers extracting and decrypting the stages to uncover the final payload.

    Pulse ID: 65e0cf54bfb52f1ba760d092
    Pulse Link: otx.alienvault.com/pulse/65e0c
    Pulse Author: AlienVault
    Created: 2024-02-29 18:39:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #DarkGate #Phishing #PDF #AlienVault

  13. 🚨 Researchers at Spamhaus have detected the circulation of an updated #DarkGate sample version 6.1.6....

    This version comes with a few changes, including:

    - a new way to decrypt its configuration
    - the removal of specific network commands

    You can find the DarkGate sample on URLhaus by @abuse_ch
    urlhaus.abuse.ch/url/2751174/

    And read more about DarkGate in Spamhaus' Q4 Botnet Threat Update:
    info.spamhaus.com/botnet-threa

    #malware #threatintel #ThreatHunting #cybersecurity

  14. 🚨 Attention aux menaces en ligne ! DarkGate, un malware polyvalent découvert en 2018, se propage via des fichiers torrent et échappe à la détection antivirus, capable de miner des cryptomonnaies, voler des données et contrôler à distance les postes de travail. 🕵️‍♂️ Avec des techniques de distribution en constante évolution, allant de l'hameçonnage aux fausses mises à jour, DarkGate se révèle être un outil de choix pour les cybercriminels, proposé même en tant que service sur des forums clandestins. 🛡️ Restez vigilants et informés pour protéger vos données et systèmes. #Cybersécurité #Malware #DarkGate
    lemagit.fr/conseil/DarkGate-ce

  15. BattleRoyal's use of email and fake updates to deliver #DarkGate and #NetSupport is unique but aligns with the overall trend Proofpoint has observed of cybercriminal threat actors adopting new, varied, and increasingly creative attack chains  to enable malware delivery.

  16. Here’s an example attack chain observed in October starting with an email that leverages 404 TDS and Keitaro TDS to deliver #DarkGate.