DarkMe RAT trades zero-days for plain phishing emails
The DarkMe RAT has shifted from using zero-day exploits to simple phishing emails, targeting corporate users to steal cryptocurrency and credentials.
The DarkMe RAT, previously linked to Water Hydra (DarkCasino) and financial traders, is now being distributed through simple phishing emails to corporate targets. Instead of using zero-day exploits, attackers send a link to a malicious .pif file disguised as an image. The malware executes a complex chain, performs an inverted sandbox check by looking for common user applications, and ultimately deploys a Visual Basic 6 RAT and infostealer focused on cryptocurrency wallets and credentials.
55