We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:Win32/Darkgate
Aliases: No associated aliases
Summary
Trojan:Win32/DarkGate is a detection of an information-stealing backdoor written in the Delphi programming language.
Some of its capabilities include taking advantage of hidden virtual network computing (hVNC); cryptocurrency mining; collecting browser data such as cookies, saved passwords, and session tokens; downloading additional malicious payloads; establishing command-and-control (C2) communication; and keylogging.
For information about DarkGate and other human-operated malware campaigns, read this blog post:
Microsoft Defender customers can turn on attack surface reduction rules to prevent common attack techniques used in infostealer infections. Attack surface reduction rules are sweeping settings that stop entire classes of threats including, infostealers, credential theft, and ransomware.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.