Skip to content

DarkGate Operator Uses Skype, Teams Messages to Distribute Malware

October 12, 2023 by Xynik

DarkGate Operator Uses Skype, Teams Messages to Distribute Malware

October 12, 2023 at 04:59PM

A threat actor is using compromised Skype and Microsoft Teams accounts to distribute DarkGate, a malware associated with information theft, keylogging, cryptocurrency mining, and ransomware. The campaign targets organizations in the Americas, and the developer of DarkGate is advertising it on underground forums and leasing it out as a service to other threat actors. Microsoft phishing via Skype and Teams is being used to deliver the malware, and organizations should enforce rules and implement security measures to prevent such attacks.

Takeaways from the meeting notes:
– A threat actor is using compromised Skype and Microsoft Teams accounts to distribute DarkGate, a malware associated with multiple malicious activities.
– The campaign has primarily targeted organizations in the Americas and has been active since August.
– The developer of DarkGate has started advertising the malware on underground forums and renting it out on a malware-as-a-service basis.
– DarkGate has recently seen a surge in activity after a period of relative inactivity.
– In the attacks analyzed, the threat actor used compromised Skype and Teams accounts to send malicious files to target recipients.
– The malware has various capabilities, including information theft, keylogging, cryptocurrency mining, and ransomware.
– DarkGate drops additional payloads once installed, including variants of DarkGate itself and the remote access Trojan, Remcos.
– Organizations should enforce rules around the use of instant messaging applications like Skype and Teams, including blocking external domains, controlling attachments, and implementing scanning measures if possible.
– Multifactor authentication is crucial to prevent threat actors from misusing illegally obtained credentials to hijack IM accounts.

Full Article

Categories Security Tags #phishing, AutoIT, Black Basta, compromised accounts, cryptocurrency miners, cryptomining, cyber-espionage, DarkGate, enterprise security, execution, information theft, instant messaging applications, keylogging, LNK file, malware leasing model, malware-as-a-service, Microsoft Teams, multifactor authentication, payload delivery, PDF file, ransomware, Remcos, remote access Trojan, rules, SharePoint, Skype, spam, surveillance, tax-related information, Teams account, threat actor, threat actors, Trend Micro, underground forums, VBA script, VBS script
Brands Beware: X’s New Badge System Is a Ripe Cyber-Target
BlackBerry Unveils Next-Generation UEM Redefining the Endpoint Management Market

Recent News

  • FTC warns of online task job scams hooking victims like gambling
  • CISA warns water facilities to secure HMI systems exposed online
  • Russia blocks Viber in latest attempt to censor communications
  • Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection
  • Russian cyberspies target Android users with new spyware
© 2025 Xynik • Built with GeneratePress