Overview
DarkGate (MITRE ATT&CK ID S1111) first emerged in 2018 and has evolved into an initial-access and data-gathering tool associated with various criminal cyber operations, per MITRE’s software profile. Written in Delphi and named “DarkGate” by its author, MITRE documents the tool as associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. MITRE’s citations note DarkGate use increased significantly starting in 2022 and that it remains under active development by its author, who provides it as a Malware-as-a-Service (MaaS) offering — a commercial criminal-service model rather than a single group’s proprietary tool.
What MITRE’s data links this to
Our ingested attack_relationships data does not currently include a group-attribution edge for DarkGate in the batch we queried — consistent with its documented Malware-as-a-Service business model, where the tool is rented to multiple, often shifting criminal customers rather than tied to one tracked group.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques MITRE links to DarkGate in our data include Additional Local or Domain Groups (T1098.007), Application Window Discovery (T1010), AutoHotKey & AutoIT (T1059.010), Automated Collection (T1119), Bypass User Account Control (T1548.002), Clipboard Data (T1115), Compute Hijacking (T1496.001) — reflecting its documented cryptomining capability — and Credentials from Password Stores (T1555).
What we don’t have
MITRE’s description text states DarkGate “first emerged in 2018,” but our ingested data doesn’t carry a structured discovery-date field. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and because DarkGate is rented as MaaS, we have no way to attribute any specific documented technique or incident to a named customer/operator.
Frequently Asked Questions
What is DarkGate? An initial-access and data-gathering malware tool, per MITRE ATT&CK, first emerging in 2018 and offered as Malware-as-a-Service since its use increased significantly in 2022.
Who uses DarkGate? Because it’s rented as Malware-as-a-Service, MITRE ATT&CK’s relationship data doesn’t tie it to one specific tracked group — it’s used by multiple, shifting criminal customers of its author.
What can DarkGate do? Per MITRE ATT&CK’s documentation and relationship data: credential theft, cryptomining (via compute hijacking), cryptotheft, and pre-ransomware access/reconnaissance.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S1111, aggregated August 26, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.