Netskope Threat Labs

DarkGate

ATP Sandbox Adv. HeuristicsNetskope IPS

DarkGate is a malware loader and remote access trojan that continues to evolve with new variants and loading approaches. Its operators rent it out as a loader, and it delivers payloads such as remote access trojans and information stealers onto infected systems, arriving through phishing, malicious documents, and abuse of messaging platforms. The loader checks its environment before deploying, and its frequent rewrites reflect an operation that invests in evading analysis.

First seen
August 2023
Last seen
October 2026
DarkgateLNKDarkGate

58 techniques across 13 tactics.

TA0042 Resource Development

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

  • T1539Steal Web Session Cookie
  • T1552Unsecured Credentials
  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1010Application Window Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery
  • T1518Software Discovery
  • T1614System Location Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Binary.Trojan.DarkGate
Document-HTML.Trojan.Darkgate
Document-HTML.Trojan.DarkGate
Document-Office.Downloader.Darkgate
Document-Office.Downloader.DarkGate
Document-Office.Trojan.Darkgate
Document-PDF.Trojan.Darkgate
Document-Word.Downloader.Darkgate
Email-MSG.Trojan.Darkgate
Script-AutoIt.Malware.DarkGate