Water Hydra, also tracked as DarkCasino and associated with Operation DarkCasino, is a financially motivated cybercriminal threat group first detected in 2021. Its targets include banks, cryptocurrency platforms, financial trading services, foreign-exchange and stock traders, gambling sites, and casinos. The group conducts targeted Windows compromises using social engineering, zero-day exploitation, and the DarkMe remote-access trojan. Water Hydra exploited the WinRAR vulnerability CVE-2023-38831 before public disclosure and subsequently weaponized CVE-2024-21412 to bypass Microsoft Defender SmartScreen. Its trader-focused campaigns distributed malicious content through foreign-exchange forums and stock-trading Telegram channels, using trading-themed images and deceptive internet shortcuts to induce execution. Infection chains have employed WebDAV-hosted payloads, Windows Installer packages, COM-based execution, layered Visual Basic loaders, obfuscation, and process hollowing. DarkMe is a Visual Basic 6 remote-access trojan and information stealer that supports remote command execution and collects host, user, antivirus, and active-window information for transmission to command-and-control infrastructure. Water Hydra deployments have established persistence through registered COM components and autorun registry entries. DarkMe is not an exclusive attribution marker: its appearance in a campaign alone does not establish Water Hydra involvement.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
“When a user opens the internet shortcut file, it exploits CVE-2024-21412 to evade Microsoft Defender SmartScreen and triggers the execution of the LNK file hosted on the same WebDAV share.” The content also uses CVE-2024-21212 once for this same infection step; this appears to be a typographical error rather than a separate vulnerability.
The group made headlines in 2023 and 2024 for weaponising two zero-days, CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen, in attacks on foreign exchange traders.
Zero-day zraniteľnosti CVE-2024-29988 a CVE-2024-26234 sú aktívne zneužívané. CVE-2024-29988 (CVSS skóre 8,8) Vysoko závažná zraniteľnosť CVE-2024-29988 umožňuje útočníkom obísť bezpečnostnú funkciu Windows SmartScreen a spustiť špeciálne pripravený škodlivý súbor. Chyba bola aktívne zneužívaná hackerskou skupinou Water Hydra.
66 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a DarkMe remote-access-trojan and espionage campaign using spear-phishing links that deliver a disguised PIF executable, followed by MSI/WSF staging, chained VB6 COM loaders, process hollowing, registry-based persistence, system profiling, cryptocurrency-wallet theft, screen capture, and command execution over a custom TCP C2 channel.
A financially motivated threat actor previously linked to DarkMe RAT. The referenced DarkMe activity historically exploited WinRAR CVE-2023-38831 and Windows Defender SmartScreen CVE-2024-21412; the latest incidents used social engineering emails delivering a .pif file rather than exploits.
Associated with earlier DarkMe activity targeting financial-market traders and cryptocurrency users; attribution for the current phishing-led DarkMe campaign remains unconfirmed.
Conducting phishing-led DarkMe campaigns. The 2026 activity uses email links masquerading as images to deliver a disguised PIF file, multi-stage obfuscated loaders, sandbox checks, and process injection; prior activity exploited WinRAR and Windows SmartScreen zero-days against foreign-exchange traders.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.