• Book Dewayne Hart
  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
  • Speaker Bio
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
Facebook-f Linkedin-in Youtube X-twitter Globe
Order books

Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware

Posted on October 20, 2023 by admin

[ad_1]

Oct 20, 2023NewsroomMalware / Cyber Attack

DarkGate Malware

Attacks leveraging the DarkGate commodity malware targeting entities in the U.K., the U.S., and India have been linked to Vietnamese actors associated with the use of the infamous Ducktail stealer.

“The overlap of tools and campaigns is very likely due to the effects of a cybercrime marketplace,” WithSecure said in a report published today. “Threat actors are able to acquire and use multiple different tools for the same purpose, and all they have to do is come up with targets, campaigns, and lures.”

Cybersecurity

The development comes amid an uptick in malware campaigns using DarkGate in recent months, primarily driven by its author’s decision to rent it out on a malware-as-a-service (MaaS) basis to other threat actors after using it privately since 2018.

It’s not just DarkGate and Ducktail, for the Vietnamese threat actor cluster responsible for these campaigns is leveraging same or very similar lures, themes, targeting, and delivery methods to also deliver LOBSHOT and RedLine Stealer.

Attack chains distributing DarkGate are characterized by the use of AutoIt scripts retrieved via a Visual Basic Script sent through phishing emails or messages on Skype or Microsoft Teams. The execution of the AutoIt script leads to the deployment of DarkGate.

In this case, however, the initial infection vector was a LinkedIn message that redirected the victim to a file hosted on Google Drive, a technique commonly used by Ducktail actors.

Cybersecurity

“Very similar campaign themes and lures have been used to deliver Ducktail and DarkGate,” WithSecure said, although the function of the final-stage differs to great extent.

While Ducktail functions as a stealer, DarkGate is a remote access trojan (RAT) with information-stealing capabilities that also establish covert persistence on the compromised hosts for backdoor access.

“DarkGate has been around for a long time and is being used by many groups for different purposes, and not just this group or cluster in Vietnam,” security researcher Stephen Robinson, senior threat intelligence analyst at WithSecure, said.

“The flipside of this is that actors can use multiple tools for the same campaign, which could obscure the true extent of their activity from purely malware-based analysis.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Recent Posts

  • Implementing a Hacker’s Mindset: Build a Security Culture That Hunts, Learns, and Wins
  • The Future of Cybersecurity Leadership: Integrating Military Discipline and Strategic Thinking
  • Prioritize to Win: Optimizing Cyber Risk for Maximum Business Impact
  • Lead Before the Breach: How Executives Prevent AI-Driven Cyber Attacks
  • Building a Human Firewall: Empowering Employees Against Cyber Threats

Recent Comments

No comments to show.

Archives

  • February 2026
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Cyber News
  • Uncategorized

Book Dewayne Hart for your next event

  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
Facebook-f Linkedin-in Youtube X-twitter Globe
© 2025 Dewayne Hart | Cybersecurity Leadership & Innovation