Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1111
MITRE ATT&CK Malware

DarkGate (S1111)

ShareXLinkedInRedditHN

[DarkGate](https://attack.mitre.org/software/S1111) first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, [DarkGate](https://attack.mitre.org/software/S1111) is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.(Citation: Ensilo Darkgate 2018) DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.(Citation: Trellix Darkgate 2023)

Platforms: Windows

▪Techniques implemented (58)

T1082System Information DiscoveryT1569.002Service ExecutionT1071.004DNST1119Automated CollectionT1574Hijack Execution FlowT1480Execution GuardrailsT1548.002Bypass User Account ControlT1622Debugger EvasionT1685Disable or Modify ToolsT1486Data Encrypted for ImpactT1566.002Spearphishing LinkT1614System Location DiscoveryT1680Local Storage DiscoveryT1010Application Window DiscoveryT1070.004File DeletionT1036.007Double File ExtensionT1547.001Registry Run Keys / Startup FolderT1041Exfiltration Over C2 ChannelT1027.013Encrypted/Encoded FileT1552Unsecured CredentialsT1005Data from Local SystemT1047Windows Management InstrumentationT1027Obfuscated Files or InformationT1490Inhibit System RecoveryT1036.003Rename Legitimate UtilitiesT1059.001PowerShellT1496.001Compute HijackingT1136.001Local AccountT1056.001KeyloggingT1059.010AutoHotKey & AutoITT1665Hide InfrastructureT1105Ingress Tool TransferT1057Process DiscoveryT1583.001DomainsT1555Credentials from Password StoresT1083File and Directory DiscoveryT1106Native APIT1140Deobfuscate/Decode Files or InformationT1204.002Malicious FileT1124System Time DiscoveryT1518.001Security Software DiscoveryT1566.001Spearphishing AttachmentT1657Financial TheftT1115Clipboard DataT1574.001DLLT1134.004Parent PID SpoofingT1574.007Path Interception by PATH Environment VariableT1539Steal Web Session CookieT1098.007Additional Local or Domain GroupsT1059.005Visual BasicT1564.001Hidden Files and DirectoriesT1529System Shutdown/RebootT1001Data ObfuscationT1497.001System ChecksT1561.001Disk Content WipeT1036MasqueradingT1055.012Process HollowingT1059.003Windows Command Shell
S1111on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.