Skip to content

Campaign record

DarkGate from Storm-1607 mail

DarkGate delivered by Storm-1607 through HTML attachments carrying a fake Word error

Status as last assessed
Dormant
First seen
2024-03-01
Last seen
2024-05-28
Indicators
16
Sources
2
Targets
Windows
  • Fake document repair prompt
  • Invoice or payment pretext
  • DarkGate
  • Matanbuchus
  • NetSupport RAT
  • HTML email attachment

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

The earliest use of this technique Microsoft records in email ran from March to June 2024 and is attributed to the group it tracks as Storm-1607. A single run in May 2024 sent tens of thousands of messages to organisations across the United States and Canada, dressed as payments or invoices, with an HTML file attached under names of the shape reports_528647.html. Opening the attachment drew a mock-up of a fresh Word document, overlaid by an error box offering to put the problem right. Pressing that button quietly loaded a command onto the clipboard; the box then changed to explain how to open Windows Terminal and paste it in. The payload was DarkGate, a commodity loader that logs keystrokes, mines coins, talks to a controller and fetches more malware. Microsoft says attaching the lure has since given way to a link pointing at a hosted page.

Cross-vendor timeline

2 published accounts. Proofpoint was first, on 2024-06-17. The most recent is Microsoft Threat Intelligence, 430 days later.

  1. 2024-06-17Proofpoint

    From Clipboard to Compromise: A PowerShell Self-Pwn

  2. 2025-08-21Microsoft Threat Intelligence+430 days

    Think before you Click(Fix): Analyzing the ClickFix social engineering technique

Dates are the publishers’ own publication dates as recorded when we retrieved each article. Publication order is not attribution: a later account may be the more complete one.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
Clipboard injection15 of 4434%T1204.004
Windows Terminal paste-and-run1 of 442%

No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

16 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenReport an error
filename, shown defanged for safety: reports_528647 dot htmlfilenameLure pageNot yet assessedReport an error in filename record b8724312-05ed-447c-a16a-4ae2467224e7
url, shown defanged for safety: hxxp colon slash slash languangjob dot com/pandstvxurlDownload URLNot yet assessed2024-05-282024-05-28Report an error in url record 316791c3-4941-47c3-b97b-1282e580f969
url, shown defanged for safety: hxxp colon slash slash mylittlecabbage dot net/qhsddxnaurlDownload URLAttacker-controlled2024-05-172024-05-17Report an error in url record 247184f6-83b4-4432-a0a5-559549f0ac4b
url, shown defanged for safety: hxxp colon slash slash mylittlecabbage dot net/xcdttafqurlDownload URLAttacker-controlled2024-05-172024-05-17Report an error in url record c204d02b-0d30-4997-9752-3012d4119525
url, shown defanged for safety: hxxps colon slash slash cdn3535 dot shop/1 dot zipurlDownload URLNot yet assessed2024-05-282024-05-28Report an error in url record c5184f35-e94d-488e-9d30-47b97715c297
url, shown defanged for safety: hxxps colon slash slash jenniferwelsh dot com/header dot pngurlDownload URLNot yet assessed2024-05-172024-05-17Report an error in url record f4bde90a-520f-45ce-802e-056ba7877678
url, shown defanged for safety: hxxps colon slash slash kostumn1 dot ilabserver dot com/1 dot zipurlDownload URLNot yet assessed2024-05-272024-05-27Report an error in url record 26a88260-298f-4709-8a76-35139a67eb99
url, shown defanged for safety: hxxps colon slash slash lashakhazhalia86dancer dot com/c dot txturlDownload URLNot yet assessed2024-05-282024-05-28Report an error in url record dfdbf170-9651-4fbb-a1ba-553cc5b4e6dd
domain, shown defanged for safety: mylittlecabbage dot netdomainCommand and controlAttacker-controlled2024-05-172024-05-17Report an error in domain record b9a32228-3dd2-424b-8bcf-2fdcb512e184
ip, shown defanged for safety: 91 dot 222 dot 173 dot 113ipCommand and controlAttacker-controlled2024-05-272024-05-27Report an error in ip record 190f13e9-3ce0-4723-b5db-e68e4c99de2b
filename, shown defanged for safety: Inkpad_honeymoon dot mspfilenameSampleNot yet assessedReport an error in filename record 950cd771-bfe4-4f11-ac5e-6487b3c77698
filename, shown defanged for safety: Inkpad3 dot dllfilenameSampleNot yet assessedReport an error in filename record dc867582-6b49-4fa6-83c5-9eaa87cd0f46
sha256, shown defanged for safety: 07e0c15adc6fcf6096dd5b0b03c20145171c00afe14100468f18f01876457c80sha256SampleNot yet assessed2024-05-272024-05-27Report an error in sha256 record 3d6b728e-8606-4bfd-9aab-04aa1a18134e
sha256, shown defanged for safety: 11909c0262563f29d28312baffb7ff027f113512c5a76bab7c5870f348ff778fsha256SampleNot yet assessed2024-03-012024-03-01Report an error in sha256 record 5215ef0e-5be5-4875-ae08-ccb8b7e5a51f
sha256, shown defanged for safety: 9701fec71e5bbec912f69c8ed63ffb6dba21b9cca7e67da5d60a72139c1795d1sha256SampleNot yet assessed2024-05-282024-05-28Report an error in sha256 record fd18418a-a397-4eaa-b26f-35f422541489
email, shown defanged for safety: rechtsanwalt at ra-silberkuhl dot comemailOtherNot yet assessed2024-05-282024-05-28Report an error in email record 8842548d-90a3-41dd-9bc9-3bb26a538c8f

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “DarkGate from Storm-1607 mail”, campaign ID 1e32ad6e, retrieved 2026-08-29, snapshot fb0eed7.

https://clickfixreport.com/campaigns/1e32ad6e/storm-1607-darkgate-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.