• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
darkgate malware exploits samba file shares in short lived campaign

DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign

You are here: Home / General Cyber Security News / DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign
July 12, 2024

Cybersecurity scientists have shed light on a small-lived DarkGate malware campaign that leveraged Samba file shares to initiate the bacterial infections.

Palo Alto Networks Unit 42 claimed the action spanned the months of March and April 2024, with the an infection chains utilizing servers working public-experiencing Samba file shares hosting Visible Primary Script (VBS) and JavaScript data files. Targets incorporated North America, Europe, and areas of Asia.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“This was a rather quick-lived marketing campaign that illustrates how risk actors can creatively abuse genuine instruments and products and services to distribute their malware,” security researchers Vishwa Thothathri, Yijie Sui, Anmol Maurya, Uday Pratap Singh, and Brad Duncan explained.

Cybersecurity

DarkGate, which very first emerged in 2018, has advanced into a malware-as-a-services (MaaS) giving utilised by a tightly controlled selection of prospects. It arrives with abilities to remotely handle compromised hosts, execute code, mine cryptocurrency, start reverse shells, and fall added payloads.

Attacks involving the malware have particularly witnessed a surge in current months in the aftermath of the multinational law enforcement takedown of the QakBot infrastructure in August 2023.

The campaign documented by Device 42 commences with Microsoft Excel (.xlsx) data files that, when opened, urge targets to click on an embedded Open up button, which, in convert, fetches and operates VBS code hosted on a Samba file share.

The PowerShell script is configured to retrieve and execute a PowerShell script, which is then utilised to down load an AutoHotKey-dependent DarkGate package deal.

Alternate sequences using JavaScript documents as a substitute of VBS are no distinctive in that they are also engineered to obtain and run the follow-up PowerShell script.

Cybersecurity

DarkGate performs by scanning for different anti-malware plans and examining the CPU details to identify if it really is working on a actual physical host or a virtual natural environment, therefore letting it to hinder examination. It also examines the host’s functioning procedures to establish the existence of reverse engineering applications, debuggers, or virtualization software.

“DarkGate C2 visitors employs unencrypted HTTP requests, but the info is obfuscated and seems as Base64-encoded text,” the researchers stated.

“As DarkGate continues to evolve and refine its strategies of infiltration and resistance to evaluation, it stays a powerful reminder of the need for sturdy and proactive cybersecurity defenses.”

Found this write-up intriguing? Adhere to us on Twitter  and LinkedIn to browse more distinctive content material we put up.


Some elements of this short article are sourced from:
thehackernews.com

Previous Post: «australian defence force private and husband charged with espionage for Australian Defence Force Private and Husband Charged with Espionage for Russia
Next Post: AT&T Confirms Data Breach Affecting Nearly All Wireless Customers at&t confirms data breach affecting nearly all wireless customers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.