DarkMe is a Windows-based Visual Basic remote-access trojan and spyware family associated with the financially motivated threat cluster tracked as Evilnum and later linked by multiple investigations to Water Hydra, also known as DarkCasino. It has been used primarily in campaigns against financial-market participants, especially forex and stock traders, with the objective of compromising trading workstations, accessing broker accounts, and enabling fraudulent financial activity.
DarkMe has been delivered through trader-focused lures distributed on trading forums, stock-trading Telegram channels, and file-sharing services, and has also been deployed via exploitation of user-interaction vulnerabilities including WinRAR CVE-2023-38831 and the Internet Shortcut/SmartScreen bypass CVE-2024-21412. Reported infection chains used crafted archives or shortcut files to trigger execution of malicious scripts and loaders that ultimately install the trojan.
The malware is described as a VB6-based RAT with long-lived builder infrastructure that remained active across multiple years. Analyses of related samples indicate command handling over custom TCP communications, use of obfuscated or reversed command strings, and persistence mechanisms including Windows autorun locations. Observed functionality supports remote shell execution and archive creation, consistent with post-compromise control of victim hosts. Campaigns linked to the same operator also used multi-stage loaders, script-based execution, AMSI bypasses, encrypted payload staging, and fileless .NET execution to deploy DarkMe or adjacent tooling.
DarkMe activity has been repeatedly tied to financially themed intrusion operations. Evilnum-linked operations used it in trader-targeting campaigns, while later Water Hydra or DarkCasino activity continued to deploy DarkMe using zero-day or n-day exploit chains against the same victim profile. The malware’s operational history, targeting, and delivery patterns place it within a broader ecosystem of financially motivated intrusion activity focused on theft, account compromise, and sustained remote access to Windows endpoints used in trading and related financial workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | On August 23, Group-IB officially documented their initial detection of DarkMe malware leveraging this vulnerability (CVE-2023-38831).
The group's DarkMe VB6 builder -- compiled in May 2022 -- is still producing active malware in March 2026, and their C2 at 91.124.98.29:2626 was confirmed live at time of investigation.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group's DarkMe VB6 builder -- compiled in May 2022 -- is still producing active malware in March 2026, and their C2 at 91.124.98.29:2626 was confirmed live at time of investigation.
The group's DarkMe VB6 builder -- compiled in May 2022 -- is still producing active malware in March 2026, and their C2 at 91.124.98.29:2626 was confirmed live at time of investigation.
The group's DarkMe VB6 builder -- compiled in May 2022 -- is still producing active malware in March 2026, and their C2 at 91.124.98.29:2626 was confirmed live at time of investigation.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The Sentinel variant is delivered via a 779KB PowerShell wrapper ( sentinel.ps1 ) that: Requests admin elevation via UAC prompt Decompresses a GZip-compressed .NET PE from an embedded byte array Writes to SubDir\Sys.exe and registers as "Runtime Broker" in HKCU\Run
The exploit allowed them to spoof file extensions, hiding the launch of malicious scripts within an archive masquerading as a '.jpg', '.txt', or any other file format.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DarkMe is a RAT used by the same operator across historical infrastructure from 2023 through 2026. The report describes DarkMe VB6 payloads delivered through layered AES-wrapped loaders, COM scriptlets, PowerShell, and JavaScript, with multiple persistence mechanisms and evolving C2 infrastructure.
A Visual Basic 6 remote access trojan built with a compile-once, patch-config builder model. It supports command execution, directory listing, file operations, ZIP archive creation, suspected screenshot capture, persistence via Run/RunOnce and COM registration, and custom TCP/UDP C2 communications using reversed UTF-16LE command strings.
Trojan payload deployed by the Water Hydra/DarkCasino threat actor as part of an attack chain (delivered after exploiting vulnerabilities, including prior WinRAR zero-days).
Trojan delivered via zero-day exploit chains used by Water Hydra.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.