PULSE NAME
Dissecting DarkGate: Modular Malware Delivery and Persistence as a Service
WHITE AlienVault 2024-02-29 Modified: 2024-03-30
21
IOCs
MEDIUM VOLUME
This report analyzes a phishing PDF that led to the delivery of a signed MSI file containing layered stages designed to avoid detection and deliver the DarkGate malware for persistence and remote access. The analysis covers extracting and decrypting the stages to uncover the final payload.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DarkGate