[object Object]
The DarkMe malware is now being delivered via simple phishing emails, abandoning the zero-days previously used to deliver the payload.
Huntress researchers report a new DarkMe malware campaign that has abandoned zero-day exploits in favor of simple social engineering. The attack begins with a phishing email delivering a .pif file disguised as an image, which uses msiexec to fetch a remote MSI installer. This installer unpacks a VB6-based malware chain that executes via a COM object registered through rundll32.exe, a technique observed in prior Water Hydra campaigns. The shift to less sophisticated initial access methods indicates a trend of broadening target lists.
72