DarkMe Email Campaign Broadens Targeting For APT RAT

    Date: 09/24/2026

    Severity: High

    Summary

    DarkMe malware was observed in two separate incidents targeting different organizations on August 31, 2026. DarkMe is a VB6-based spy-RAT previously linked to the financially motivated Water Hydra and Operation DarkCasino. The samples were identified through their command set, VB6 loader chain, and a modified RC4 routine that produces a single-byte XOR payload. DarkMe previously exploited CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen to deliver the malware. In the latest incidents, attackers did not use exploits and instead relied on social engineering, convincing victims to execute a `.pif` file delivered through email.

    Indicators of Compromise (IOC) List

    Domains/URLs

    onlineview365.com

    readonline365.com

    thatawful.boutique

    IP Address

    67.43.50.11

    Hash

    394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04

    9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f

    1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918

    52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a

    4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0

    3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634

    d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93

    54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76

    2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37

    Filepath

    %AppData%\ComponentsFolder\

    Registry Key

    HKCU\Software\Classes\Locked\shell\open\command

    Run Key

    explorer.exe "Locked://Newest"

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection               

    Detection Query 1 :

    domainname like "onlineview365.com" or url like "onlineview365.com" or siteurl like "onlineview365.com" or domainname like "readonline365.com" or url like "readonline365.com" or siteurl like "readonline365.com" or domainname like "thatawful.boutique" or url like "thatawful.boutique" or siteurl like "thatawful.boutique"

    Detection Query 2 :

    dstipaddress IN ("67.43.50.11") or srcipaddress IN ("67.43.50.11")

    Detection Query 3 :

    sha256hash IN ("2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37","1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918","9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f","54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76","4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0","3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634","d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93","394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04","52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and objectname like "%AppData%\ComponentsFolder\"

    Detection Query 5 :

    technologygroup = "EDR" and objectname like "%AppData%\ComponentsFolder\"

    Detection Query 6 :

    datasourcename = "Windows Security" and eventtype = "4657" and objecttype like "HKCU\Software\Classes\Locked\shell\open\command"

    Detection Query 7 :

    technologygroup = "EDR" and objecttype like "HKCU\Software\Classes\Locked\shell\open\command"

    Reference:

    https://www.huntress.com/blog/darkme-rat-abandons-exploits


    Tags

    MalwareVulnerabilityCVE-2023CVE - 2024APTRATWinRARWater and Wastewater SectorFinancial ServicesLoaderExploitSocial Engineering

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags