Campaign record
DarkGate from Storm-1607 mail
DarkGate delivered by Storm-1607 through HTML attachments carrying a fake Word error
- Status as last assessed
- Dormant
- First seen
- 2024-03-01
- Last seen
- 2024-05-28
- Indicators
- 16
- Sources
- 2
- Targets
- Windows
- Fake document repair prompt
- Invoice or payment pretext
- DarkGate
- Matanbuchus
- NetSupport RAT
- HTML email attachment
Original research
- Proofpoint2024-06-17Vendor research
From Clipboard to Compromise: A PowerShell Self-Pwn
- Microsoft Threat Intelligence2025-08-21Vendor researchFirst account
Think before you Click(Fix): Analyzing the ClickFix social engineering technique
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
The earliest use of this technique Microsoft records in email ran from March to June 2024 and is attributed to the group it tracks as Storm-1607. A single run in May 2024 sent tens of thousands of messages to organisations across the United States and Canada, dressed as payments or invoices, with an HTML file attached under names of the shape reports_528647.html. Opening the attachment drew a mock-up of a fresh Word document, overlaid by an error box offering to put the problem right. Pressing that button quietly loaded a command onto the clipboard; the box then changed to explain how to open Windows Terminal and paste it in. The payload was DarkGate, a commodity loader that logs keystrokes, mines coins, talks to a controller and fetches more malware. Microsoft says attaching the lure has since given way to a link pointing at a hosted page.
Cross-vendor timeline
2 published accounts. Proofpoint was first, on 2024-06-17. The most recent is Microsoft Threat Intelligence, 430 days later.
- 2024-06-17Proofpoint
From Clipboard to Compromise: A PowerShell Self-Pwn
- 2025-08-21Microsoft Threat Intelligence+430 days
Think before you Click(Fix): Analyzing the ClickFix social engineering technique
Dates are the publishers’ own publication dates as recorded when we retrieved each article. Publication order is not attribution: a later account may be the more complete one.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
| Clipboard injection | 15 of 4434% | T1204.004 |
| Windows Terminal paste-and-run | 1 of 442% | — |
No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
16 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| filename, shown defanged for safety: reports_528647 dot html | filename | Lure page | Not yet assessed | — | — | Report an error in filename record b8724312-05ed-447c-a16a-4ae2467224e7 |
| url, shown defanged for safety: hxxp colon slash slash languangjob dot com/pandstvx | url | Download URL | Not yet assessed | 2024-05-28 | 2024-05-28 | Report an error in url record 316791c3-4941-47c3-b97b-1282e580f969 |
| url, shown defanged for safety: hxxp colon slash slash mylittlecabbage dot net/qhsddxna | url | Download URL | Attacker-controlled | 2024-05-17 | 2024-05-17 | Report an error in url record 247184f6-83b4-4432-a0a5-559549f0ac4b |
| url, shown defanged for safety: hxxp colon slash slash mylittlecabbage dot net/xcdttafq | url | Download URL | Attacker-controlled | 2024-05-17 | 2024-05-17 | Report an error in url record c204d02b-0d30-4997-9752-3012d4119525 |
| url, shown defanged for safety: hxxps colon slash slash cdn3535 dot shop/1 dot zip | url | Download URL | Not yet assessed | 2024-05-28 | 2024-05-28 | Report an error in url record c5184f35-e94d-488e-9d30-47b97715c297 |
| url, shown defanged for safety: hxxps colon slash slash jenniferwelsh dot com/header dot png | url | Download URL | Not yet assessed | 2024-05-17 | 2024-05-17 | Report an error in url record f4bde90a-520f-45ce-802e-056ba7877678 |
| url, shown defanged for safety: hxxps colon slash slash kostumn1 dot ilabserver dot com/1 dot zip | url | Download URL | Not yet assessed | 2024-05-27 | 2024-05-27 | Report an error in url record 26a88260-298f-4709-8a76-35139a67eb99 |
| url, shown defanged for safety: hxxps colon slash slash lashakhazhalia86dancer dot com/c dot txt | url | Download URL | Not yet assessed | 2024-05-28 | 2024-05-28 | Report an error in url record dfdbf170-9651-4fbb-a1ba-553cc5b4e6dd |
| domain, shown defanged for safety: mylittlecabbage dot net | domain | Command and control | Attacker-controlled | 2024-05-17 | 2024-05-17 | Report an error in domain record b9a32228-3dd2-424b-8bcf-2fdcb512e184 |
| ip, shown defanged for safety: 91 dot 222 dot 173 dot 113 | ip | Command and control | Attacker-controlled | 2024-05-27 | 2024-05-27 | Report an error in ip record 190f13e9-3ce0-4723-b5db-e68e4c99de2b |
| filename, shown defanged for safety: Inkpad_honeymoon dot msp | filename | Sample | Not yet assessed | — | — | Report an error in filename record 950cd771-bfe4-4f11-ac5e-6487b3c77698 |
| filename, shown defanged for safety: Inkpad3 dot dll | filename | Sample | Not yet assessed | — | — | Report an error in filename record dc867582-6b49-4fa6-83c5-9eaa87cd0f46 |
| sha256, shown defanged for safety: 07e0c15adc6fcf6096dd5b0b03c20145171c00afe14100468f18f01876457c80 | sha256 | Sample | Not yet assessed | 2024-05-27 | 2024-05-27 | Report an error in sha256 record 3d6b728e-8606-4bfd-9aab-04aa1a18134e |
| sha256, shown defanged for safety: 11909c0262563f29d28312baffb7ff027f113512c5a76bab7c5870f348ff778f | sha256 | Sample | Not yet assessed | 2024-03-01 | 2024-03-01 | Report an error in sha256 record 5215ef0e-5be5-4875-ae08-ccb8b7e5a51f |
| sha256, shown defanged for safety: 9701fec71e5bbec912f69c8ed63ffb6dba21b9cca7e67da5d60a72139c1795d1 | sha256 | Sample | Not yet assessed | 2024-05-28 | 2024-05-28 | Report an error in sha256 record fd18418a-a397-4eaa-b26f-35f422541489 |
| email, shown defanged for safety: rechtsanwalt at ra-silberkuhl dot com | Other | Not yet assessed | 2024-05-28 | 2024-05-28 | Report an error in email record 8842548d-90a3-41dd-9bc9-3bb26a538c8f |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “DarkGate from Storm-1607 mail”, campaign ID 1e32ad6e, retrieved 2026-08-29, snapshot fb0eed7.
https://clickfixreport.com/campaigns/1e32ad6e/storm-1607-darkgate-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.