DarkMe RAT is a Windows-focused Visual Basic 6 remote-access trojan associated with the Water Hydra, also known as DarkCasino, threat activity. Campaign activity surged in February 2024 and exploited CVE-2024-21412. Observed execution chains use a shortcut-based lure, remotely retrieved scripts and installer components, COM registration, layered decryption, and process hollowing to launch the final obfuscated payload. DarkMe establishes persistence through COM registration and a current-user Run entry. It collects host and user identifiers, victim country, installed antivirus products, and foreground-window titles, then transmits collected information to its command-and-control infrastructure over socket-based communications. The implant supports asynchronous command execution, including shell execution, file and directory operations, directory enumeration, archive creation, and system reconnaissance. DarkMe uses encoded strings, garbage code, control-flow obfuscation, and process hollowing to hinder analysis and detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A spike in distributing DarkMe RAT was observed in February 2024, exploiting the zero-day (CVE-2024-21412) by the hacking group Water Hydra. | A spike in distributing DarkMe RAT was observed in February 2024, exploiting the zero-day CVE-2024-21412 by the hacking group Water Hydra.
DarkMe RAT is the signature malware of the WaterHydra/DarkCasino APT group. Seven DarkMe samples were found sharing the same C2 IP as the QuasarRAT deployment. DarkMe is a custom VB6 RAT with reversed UTF-16LE command strings, a SOCKET_WINDOW class for asynchronous C2 communication, and a command set including shell execution (SHLEXE), file operations, directory mapping, ZIP archive creation, and system reconnaissance.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A spike in distributing DarkMe RAT was observed in February 2024, exploiting the zero-day CVE-2024-21412 by the hacking group Water Hydra.
DarkMe RAT is the signature malware of the WaterHydra/DarkCasino APT group. Seven DarkMe samples were found sharing the same C2 IP as the QuasarRAT deployment. DarkMe is a custom VB6 RAT with reversed UTF-16LE command strings, a SOCKET_WINDOW class for asynchronous C2 communication, and a command set including shell execution (SHLEXE), file operations, directory mapping, ZIP archive creation, and system reconnaissance.
DarkMe RAT is the signature malware of the WaterHydra/DarkCasino APT group. Seven DarkMe samples were found sharing the same C2 IP as the QuasarRAT deployment. DarkMe is a custom VB6 RAT with reversed UTF-16LE command strings, a SOCKET_WINDOW class for asynchronous C2 communication, and a command set including shell execution (SHLEXE), file operations, directory mapping, ZIP archive creation, and system reconnaissance.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping Technique ID Technique Usage T1059.001 PowerShell Multi-stage PS1 loaders with AMSI bypass
A URL-hosted batch script downloads the MSI file into the %temp% folder and starts its execution.
MITRE ATT&CK Mapping Technique ID Technique Usage T1059.005 Visual Basic DarkMe VB6 RAT, forex.sct COM scriptlet
A spike in distributing DarkMe RAT was observed in February 2024, exploiting the zero-day (CVE-2024-21412) by the hacking group Water Hydra.
DarkMe EXE variants write to HKLM\...\RunOnce\*RD_ via WScript.Shell.RegWrite ... MITRE ATT&CK Mapping Technique ID Usage Modify Registry T1112 COM object persistence, Run keys
The malware creates a suspended process for a legitimate file “%appdata%\ProductConfigurations\WINDBVERS.EXE” and resumes its execution after loading the DarkMe RAT malware code using process hollowing.
The Visual Basic compiled DarkMe RAT executable is highly obfuscated... The malware keeps the strings encoded, decoding them before use.
6. MITRE ATT&CK Mapping Technique ID Usage Masquerading T1036 AnyDesk disguised as legitimate remote support
MITRE ATT&CK Mapping Technique ID Technique Usage T1036.001 Invalid Code Signature Fake "Microsoft Corporation" and "Microsoft Windows Publisher" certs
[8] Process Masquerading Drops as: RuntimeBroker.exe, ctfmon.exe, dwm.exe, TextInputHost.exe, chrome_update.exe, edge_update.exe, windows_update.exe
The malware creates a suspended process for a legitimate file “%appdata%\ProductConfigurations\WINDBVERS.EXE” and resumes its execution after loading the DarkMe RAT malware code using process hollowing.
Windows Installer (msiexec.exe) extracts files from “oxc.msi” and starts executing the DLL file.
[2] Execution Variants forex.sct -> COM scriptlet via regsvr32 (LOLBin, CLSID FEEDACDC)
The malware gets the active window name using the APIs GetForegroundWindow and GetWindowTextA.
The malware retrieves the computer name and username information from the environment variables.
The malware collects various information from the victim’s machine, including... computer name...
If the malware is being debugged using the IDA debugger, threat actors will receive the active window name as “IDA” and can avoid further communication with the targeted machine.
MITRE ATT&CK Mapping Technique ID Technique Usage T1071.001 Web Protocols GitHub raw content for payload staging
The malware gets the IP address for the decrypted C2 host using the API gethostbyname and uses socket APIs for communicating with the C2 server.
The batch script is responsible for downloading and executing the malicious Microsoft Installer File (MSI).
6. MITRE ATT&CK Mapping Technique ID Usage Remote Access Software T1219 AnyDesk for persistent operator access to C2 infrastructure
6. MITRE ATT&CK Mapping Technique ID Usage Non-Standard Port T1571 AnyDesk on 7070, DarkMe on 4242
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan with C2 infrastructure observed on port 4242; the report describes AnyDesk being used by the operator to manage Windows servers hosting DarkMe RAT C2 components.
A custom VB6 remote access trojan associated with WaterHydra/DarkCasino. It provides shell execution, file operations, directory mapping, ZIP archive creation, reconnaissance, screenshot capability, and keylogging.
An obfuscated Visual Basic remote-access trojan delivered through an LNK/MSI/COM-DLL execution chain. It establishes Run-key persistence, performs process hollowing, collects host, user, antivirus, country, and active-window information, exfiltrates it to an RC4-protected C2 server, and accepts asynchronous C2 commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.