Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DarkGate

100
Global rank
71 infographic chevron month
Month rank
77 infographic chevron week
Week rank
0
IOCs

DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors.

Loader
Type
ex-USSR
Origin
15 November, 2018
First seen
28 June, 2026
Last seen
Also known as
Meh

How to analyze DarkGate with ANY.RUN

Type
ex-USSR
Origin
15 November, 2018
First seen
28 June, 2026
Last seen

IOCs

IP addresses
5.252.177.24
82.102.157.154
45.147.228.138
5.252.178.193
5.45.72.213
195.123.233.165
203.150.226.21
64.190.113.222
82.102.165.17
184.151.210.103
87.106.16.115
195.123.241.144
82.102.149.157
195.123.233.206
188.246.224.221
103.124.106.237
5.252.177.226
5.252.177.213
118.174.64.219
82.102.165.166
Hashes
93b2ff7f3570b4d91283027e41cbf1ce1f1f3b452d739a66c112612c664d9672
46c785b72c3e85f73e621ca12e1a92bd00ea0153833ed46ad574b0242013a818
bae22f27c12bce1faeb64b6eb733302aff5867baa8eed832397a7ce284a86ff4
b79b536569c0060a834e4001289a6700692d67df58e644779fababf0df22fc75
ca2af2316629b492968b1ccd2548bd4031d6722b726bac694f00380cd320b510
8979e74303550e257eb92225507bf2fb128cebde5f3f6e36b4236e822e194f64
8a88083a6168893eae13e60aed817aae6342bd84c66c95dc0e2e8d5054a8885d
761637d44066023ec2207240c658f7a4ada3777f31d653b8a220eb47c754f066
301158ffb44a9824deeec16bdc7dabdc328b9f3ecde0df048741218285d8bcc8
2824b4f5365025f5b0cb2bc956c2a46336fde086e0d56625d50375b6374251c8
4c324a8f0f395dc9a69854ec9c3917ac2bc9809a7a585c8b0c0e786f02a564d8
2b24c4c883a562d0326846ee1c92840144d1d755cdb721b24a35038ea92aa0e4
64db719c67988b106bf2d1a5b842445e8ff9b6436be28bcaa0b8876d330f8168
b0648d3e4f8eb5c0c83083be84748e39fffe64aec7bdefc3634193b181935e3d
c17d11aee8e1bb6d556849b44670b002c4df26dd141fdac36fd60f6b58d629f1
7fc3126b9c53816657076b62188f9905067ec4b070deea5999cd6d7aa3c85c76
0f1545a7176c45b0e7f9198cac8972167e5846e8b84cd40926f7edf338eeace2
Domains
streammobs.com
cousidporke.icu
datasyncllc.net
akamai.la
hardwarenet.cc
reactervnamnat.com
evil.gift
xfirecovery.pro
diskonline.net
screenshot.photos
iamupdate.com
sanibroadbandcommunicton.duckdns.org
advancedscannerip.com
awsamazon.cc
a-1bcdn.com
drkgatevservicceoffice.net
battlenet.la
ec2-14-122-45-127.compute-1.amazonaws.cdnprivate.tel
onlysportsfitnessam.com
intranet.mcasavaya.com
URLs
http://94.228.169.143/
http://zochao.com/
http://sanibroadbandcommunicton.duckdns.org/
http://5.188.87.58/
http://cdn-ext.net/
http://45.142.212.99/
http://joagfhreetdsa.com/
http://piret-wismann.com/
http://hgfdytrywq.com/
http://whoernet.co.com/
http://185.130.227.202/
http://vintagecarsforlife.com/
http://prestige-castom.com/
http://127.0.0.1:65432/SSO
http://getldrrgoodgame.com/
http://87.106.16.115:9061/
http://80.66.88.145/
http://cheneseemeg7575.cash/
http://annoyingannoying.vodka/
http://uiahbmajokriswhoer.net/
Last Seen at

Recent blog posts

post image
ANY.RUN & Torq Integration: Scale Triage...
watchers 3267
comments 0
post image
From Alert Enrichment to Confident Response:...
watchers 5669
comments 0
post image
EvilTokens: How “Ghost” Code Threatens US and...
watchers 8348
comments 0

What is DarkGate malware?

DarkGate is a loader malware family that was first detected in 2018 and has since been continuously undergoing serious development, significantly expanding its functionality. This malicious software is notable for the use of various evasion techniques, such as process hollowing.

It is distributed based on the malware-as-a-service (MaaS) model by its developer who goes by the name RastaFarEye on popular Darkweb forums. According to the creator of the malware, they have been developing it since 2017.

As of the beginning of 2024, RastaFarEye offers only 30 seats per month to those willing to purchase a subscription, which is priced at $15,000/mo. The malware has been observed to be used by known threat actors in different attacks involving data theft and extortion. Operators get to control the malware via a special panel.

Expose malicious activities and get IOCs with ANY.RUN sandbox

  • Analyze malware in Windows 7, 10, and 11 VMs
  • Interact with files and links, just like on your own computer
  • Work in a private team space with your colleagues
Request 14-day free trial

Technical details of the DarkGate malicious software

DarkGate is a multi-functional malware, meaning that it can be employed for a range of malicious purposes. Here is an overview of its key capabilities:

  • DarkGate can execute malware to memory, making it more difficult to detect and remove.
  • It can remotely control the victim's computer, giving the attacker complete access to the victim's data and system, as well as log its keystrokes and take screenshots.
  • DarkGate can browse and manage files on the victim's computer.
  • It can steal the victim's passwords, credit card numbers, cookies, history, and other sensitive information from their web browsers.
  • The malware can gain administrator privileges on the victim's computer, giving the attacker even more control over the system.
  • DarkGate can steal the victim's Discord login token, which can be used to log in to their account and steal their data.
  • It is also equipped with a cryptominer, allowing operators to mine various cryptocurrencies using the victim's computer's CPU and/or GPU.

The DarkGate virus achieves persistence, making sure it stays on the computer even after a restart, in several ways. For instance, it can create a shortcut in the Startup folder or change a setting in the registry. Additionally, it employs Asynchronous Process Call injection.

In order to evade antivirus software, DarkGate has the functionality to check the presence of a list of popular security products on the system. It also has an anti-sandboxing capability, where it can detect a virtual machine environment and halt or adjust its execution.

All the communication with the command and control (C2) server is performed via HTTP and is obfuscated.

Execution process of DarkGate attacks

Despite having an anti-sandboxing capability, DarkGate can be easily analyzed in ANY.RUN. As a result, we can easily detect the malware and observe its activity by simply uploading its sample to the sandbox.

DarkGate threat details shown in ANY.RUN DarkGate`s threat details demonstrated in ANY.RUN

The execution chain of DarkGate may vary depending on the versions and other factors. In some instances, the entire execution chain is contained in a single file that facilitates all activities post-infection. Let's examine our sample.

DarkGate may perform process hollowing into certain processes within the infected operating system. This can include TabTip32, BraveUpdate, MicrosoftEdgeUpdate, ielowutil, or, in our case, GoogleUpdate. This malware often utilizes AutoIT scripts and files for injection and execution of shellcode and other malicious activities. The primary malicious activities are executed through the injected GoogleUpdate process. It adds itself to the startup directory, checks for the presence of antivirus software, connects to the command and control server (C2), downloads payloads, and more.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gathering threat intelligence on Darkgate malware

To collect up-to-date intelligence on Darkgate, use Threat Intelligence Lookup.

This service gives you access to a vast database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox.

With over 40 customizable search parameters, including IPs, domains, file names, and process artifacts, you can efficiently gather relevant data on threats like Darkgate.

Darkgate ANY.RUN Search results for Darkgate in Threat Intelligence Lookup

For example, you can search directly for the threat name or use related indicators like hash values or network connections. Submitting a query such as threatName:"darkgate" AND domainName:"" will generate a list of files, events, domain names, and other data extracted from DarkGate samples along with sandbox sessions that you can explore in detail to gain comprehensive insights into this malware’s behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Distribution methods of the DarkGate malware

Like other common malware families, including Remcos and njRAT, DarkGate infiltrates systems through deceptive emails.

However, instead of directly embedding malware into an email attachment, DarkGate typically utilizes malicious links that direct users to compromised websites hosting MSI installer files. When unsuspecting users download and execute these infected MSIs, the DarkGate malware silently installs itself on their computers. Once embedded, DarkGate begins to steal sensitive information and perform other similar actions.

Conclusion

DarkGate is an extremely capable malware that is operated by infamous threat groups, which puts it on a list of major cybersecurity concerns. To ensure your organization has the capacity to avoid becoming another victim of the malware, you need to have access to up-to-date information on DarkGate.

Utilize the ANY.RUN sandbox to examine the latest samples of DarkGate and gather up-to-date insights into their behavior patterns. Uncover the TTPs employed by the malware and collect its indicators of compromise. Leverage ANY.RUN's interactive malware analysis approach to safely interact with the malware as if on your own device, extracting even more relevant information.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More