home.social

#darkme — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #darkme, aggregated by home.social.

  1. 📢 DarkMe RAT : Water Hydra abandonne les zero-days pour le phishing par fichier .pif

    Cet article documente deux incidents distincts détectés le 31 août 2026 impliquant le malware DarkMe, un RAT/espion écrit en Visual Basic 6 (VB6) précédemment attribué au groupe APT Water Hydra (alias EvilNum / Operation DarkCasino).

    📖 cyberveille : cyberveille.ch/posts/2026-09-2
    🌐 source : huntress.com/blog/darkme-rat-a
    🟢 vérification factuelle haute
    #DarkMe #WaterHydra #Cyberveille

  2. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    Pulse ID: 6ab4b67623ce010ee0dba6a4
    Pulse Link: otx.alienvault.com/pulse/6ab4b
    Pulse Author: Tr1sa111
    Created: 2026-09-24 05:34:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #InfoStealer #RAT #Trojan #OTX #Tr1sa111

  3. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    Pulse ID: 6ab4b67623ce010ee0dba6a4
    Pulse Link: otx.alienvault.com/pulse/6ab4b
    Pulse Author: Tr1sa111
    Created: 2026-09-24 05:34:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #InfoStealer #RAT #Trojan #OTX #Tr1sa111

  4. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    Pulse ID: 6ab4b67623ce010ee0dba6a4
    Pulse Link: otx.alienvault.com/pulse/6ab4b
    Pulse Author: Tr1sa111
    Created: 2026-09-24 05:34:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #InfoStealer #RAT #Trojan #OTX #Tr1sa111

  5. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    Pulse ID: 6ab4b67623ce010ee0dba6a4
    Pulse Link: otx.alienvault.com/pulse/6ab4b
    Pulse Author: Tr1sa111
    Created: 2026-09-24 05:34:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #InfoStealer #RAT #Trojan #OTX #Tr1sa111

  6. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    DarkMe, a Visual Basic 6 spy-RAT previously linked to financially-motivated APT group Water Hydra, was observed in two separate incidents affecting organizations in August 2026. Previously notable for weaponizing zero-day exploits including CVE-2023-38831 and CVE-2024-21412, this campaign abandoned sophisticated exploits in favor of basic social engineering tactics. Victims received phishing emails containing links disguised as images that delivered PIF executables. The attack chain utilized MSI installers, VB6 loaders, COM objects, and process hollowing into legitimate signed Microsoft binaries. Novel tradecraft includes using PIF files as initial payloads and implementing custom protocol handlers for persistence. The malware targets cryptocurrency wallets, password managers, trading platforms, and gaming applications, employing an inverted sandbox check against 329 applications to identify genuine user environments rather than analysis systems. This shift from targeted, exploit-driven operations to high-...

    Pulse ID: 6ab326f4234e22940c7fb969
    Pulse Link: otx.alienvault.com/pulse/6ab32
    Pulse Author: AlienVault
    Created: 2026-09-23 01:10:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #RAT #InfoStealer #CVE202338831 #OTX #AlienVault

  7. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    DarkMe, a Visual Basic 6 spy-RAT previously linked to financially-motivated APT group Water Hydra, was observed in two separate incidents affecting organizations in August 2026. Previously notable for weaponizing zero-day exploits including CVE-2023-38831 and CVE-2024-21412, this campaign abandoned sophisticated exploits in favor of basic social engineering tactics. Victims received phishing emails containing links disguised as images that delivered PIF executables. The attack chain utilized MSI installers, VB6 loaders, COM objects, and process hollowing into legitimate signed Microsoft binaries. Novel tradecraft includes using PIF files as initial payloads and implementing custom protocol handlers for persistence. The malware targets cryptocurrency wallets, password managers, trading platforms, and gaming applications, employing an inverted sandbox check against 329 applications to identify genuine user environments rather than analysis systems. This shift from targeted, exploit-driven operations to high-...

    Pulse ID: 6ab326f4234e22940c7fb969
    Pulse Link: otx.alienvault.com/pulse/6ab32
    Pulse Author: AlienVault
    Created: 2026-09-23 01:10:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #RAT #InfoStealer #CVE202338831 #OTX #AlienVault

  8. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    DarkMe, a Visual Basic 6 spy-RAT previously linked to financially-motivated APT group Water Hydra, was observed in two separate incidents affecting organizations in August 2026. Previously notable for weaponizing zero-day exploits including CVE-2023-38831 and CVE-2024-21412, this campaign abandoned sophisticated exploits in favor of basic social engineering tactics. Victims received phishing emails containing links disguised as images that delivered PIF executables. The attack chain utilized MSI installers, VB6 loaders, COM objects, and process hollowing into legitimate signed Microsoft binaries. Novel tradecraft includes using PIF files as initial payloads and implementing custom protocol handlers for persistence. The malware targets cryptocurrency wallets, password managers, trading platforms, and gaming applications, employing an inverted sandbox check against 329 applications to identify genuine user environments rather than analysis systems. This shift from targeted, exploit-driven operations to high-...

    Pulse ID: 6ab326f4234e22940c7fb969
    Pulse Link: otx.alienvault.com/pulse/6ab32
    Pulse Author: AlienVault
    Created: 2026-09-23 01:10:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #RAT #InfoStealer #CVE202338831 #OTX #AlienVault

  9. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    DarkMe, a Visual Basic 6 spy-RAT previously linked to financially-motivated APT group Water Hydra, was observed in two separate incidents affecting organizations in August 2026. Previously notable for weaponizing zero-day exploits including CVE-2023-38831 and CVE-2024-21412, this campaign abandoned sophisticated exploits in favor of basic social engineering tactics. Victims received phishing emails containing links disguised as images that delivered PIF executables. The attack chain utilized MSI installers, VB6 loaders, COM objects, and process hollowing into legitimate signed Microsoft binaries. Novel tradecraft includes using PIF files as initial payloads and implementing custom protocol handlers for persistence. The malware targets cryptocurrency wallets, password managers, trading platforms, and gaming applications, employing an inverted sandbox check against 329 applications to identify genuine user environments rather than analysis systems. This shift from targeted, exploit-driven operations to high-...

    Pulse ID: 6ab326f4234e22940c7fb969
    Pulse Link: otx.alienvault.com/pulse/6ab32
    Pulse Author: AlienVault
    Created: 2026-09-23 01:10:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DarkMe #RAT #InfoStealer #CVE202338831 #OTX #AlienVault