DarkMe Shifts From Zero-Days to Phishing Emails
Researchers say DarkMe, tied to Water Hydra, now uses phishing .pif files instead of zero-days to steal crypto and credentials from corporate users.
Huntress reported on 22 September 2026 that a DarkMe campaign seen in a customer environment has abandoned zero-day exploits for simple phishing. Help Net Security, writing the next day, identifies DarkMe as a Visual Basic 6 RAT and infostealer previously tied to Water Hydra (DarkCasino) and financial traders, now aimed at everyday corporate users. Both describe a malicious .pif file presented as an image; Help Net Security specifies a PNG reached by a link, while Huntress says the email delivers the .pif and also refers to phishing links. Huntress describes msiexec fetching a remote MSI, then a wrapper and three VB6 loaders that execute through a COM object registered with rundll32.exe, consistent with earlier Water Hydra technique. Help Net Security adds an inverted sandbox check for common user applications before theft of crypto wallets and credentials and screenshot capture. The sources agree the less sophisticated access is meant to widen the victim set beyond traders.
- Huntress (2026-09-22) observed the campaign in a customer environment; Help Net Security reported it on 2026-09-23.
- DarkMe, a Visual Basic 6 RAT and infostealer previously linked to Water Hydra (DarkCasino) and financial traders, has dropped earlier zero-day delivery.
- Initial access is now simple phishing with a malicious .pif file disguised as an image; Help Net Security specifies a PNG delivered by link, while Huntress describes the email delivering the .pif and also mentions phishing links.
- Huntress: the chain uses msiexec to fetch a remote MSI, a wrapper, and three VB6 loaders, then runs via a COM object registered with rundll32.exe, a pattern seen in prior Water Hydra activity.
- Help Net Security: the malware uses an inverted sandbox check that looks for common user applications, then steals cryptocurrency wallets and credentials and takes screenshots.
- Both sources say the simpler method broadens targeting from financial traders to everyday corporate users.
Coverage timelineoldest first · each row is one article
- · 4d ago[object Object]
Huntress· 72
The DarkMe malware is now being delivered via simple phishing emails, abandoning the zero-days previously used to deliver the payload.
- · 3d agoDarkMe RAT trades zero-days for plain phishing emails
Help Net Security· 55
The DarkMe RAT has shifted from using zero-day exploits to simple phishing emails, targeting corporate users to steal cryptocurrency and credentials.