Skip to main content
QUIETLYTIC
Malware

DarkGate

Initial-access and data-gathering tool, per MITRE ATT&CK, first emerging in 2018 and offered as Malware-as-a-Service since its use increased significantly starting in 2022.

Threat Level
HIGH
Family
DarkGate
Type
OTHER

Overview

DarkGate (MITRE ATT&CK ID S1111) first emerged in 2018 and has evolved into an initial-access and data-gathering tool associated with various criminal cyber operations, per MITRE’s software profile. Written in Delphi and named “DarkGate” by its author, MITRE documents the tool as associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. MITRE’s citations note DarkGate use increased significantly starting in 2022 and that it remains under active development by its author, who provides it as a Malware-as-a-Service (MaaS) offering — a commercial criminal-service model rather than a single group’s proprietary tool.

Our ingested attack_relationships data does not currently include a group-attribution edge for DarkGate in the batch we queried — consistent with its documented Malware-as-a-Service business model, where the tool is rented to multiple, often shifting criminal customers rather than tied to one tracked group.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to DarkGate in our data include Additional Local or Domain Groups (T1098.007), Application Window Discovery (T1010), AutoHotKey & AutoIT (T1059.010), Automated Collection (T1119), Bypass User Account Control (T1548.002), Clipboard Data (T1115), Compute Hijacking (T1496.001) — reflecting its documented cryptomining capability — and Credentials from Password Stores (T1555).

What we don’t have

MITRE’s description text states DarkGate “first emerged in 2018,” but our ingested data doesn’t carry a structured discovery-date field. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and because DarkGate is rented as MaaS, we have no way to attribute any specific documented technique or incident to a named customer/operator.

Frequently Asked Questions

What is DarkGate? An initial-access and data-gathering malware tool, per MITRE ATT&CK, first emerging in 2018 and offered as Malware-as-a-Service since its use increased significantly in 2022.

Who uses DarkGate? Because it’s rented as Malware-as-a-Service, MITRE ATT&CK’s relationship data doesn’t tie it to one specific tracked group — it’s used by multiple, shifting criminal customers of its author.

What can DarkGate do? Per MITRE ATT&CK’s documentation and relationship data: credential theft, cryptomining (via compute hijacking), cryptotheft, and pre-ransomware access/reconnaissance.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S1111, aggregated August 26, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools