Date: 09/24/2026
Severity: High
Summary
DarkMe malware was observed in two separate incidents targeting different organizations on August 31, 2026. DarkMe is a VB6-based spy-RAT previously linked to the financially motivated Water Hydra and Operation DarkCasino. The samples were identified through their command set, VB6 loader chain, and a modified RC4 routine that produces a single-byte XOR payload. DarkMe previously exploited CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen to deliver the malware. In the latest incidents, attackers did not use exploits and instead relied on social engineering, convincing victims to execute a `.pif` file delivered through email.
Indicators of Compromise (IOC) List
Domains/URLs | onlineview365.com readonline365.com thatawful.boutique |
IP Address | 67.43.50.11 |
Hash | 394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04
9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f
1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918
52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a
4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0
3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634
d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93
54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76
2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37
|
Filepath | %AppData%\ComponentsFolder\ |
Registry Key | HKCU\Software\Classes\Locked\shell\open\command |
Run Key | explorer.exe "Locked://Newest" |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "onlineview365.com" or url like "onlineview365.com" or siteurl like "onlineview365.com" or domainname like "readonline365.com" or url like "readonline365.com" or siteurl like "readonline365.com" or domainname like "thatawful.boutique" or url like "thatawful.boutique" or siteurl like "thatawful.boutique" |
Detection Query 2 : | dstipaddress IN ("67.43.50.11") or srcipaddress IN ("67.43.50.11") |
Detection Query 3 : | sha256hash IN ("2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37","1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918","9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f","54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76","4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0","3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634","d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93","394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04","52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4663" and objectname like "%AppData%\ComponentsFolder\" |
Detection Query 5 : | technologygroup = "EDR" and objectname like "%AppData%\ComponentsFolder\" |
Detection Query 6 : | datasourcename = "Windows Security" and eventtype = "4657" and objecttype like "HKCU\Software\Classes\Locked\shell\open\command" |
Detection Query 7 : | technologygroup = "EDR" and objecttype like "HKCU\Software\Classes\Locked\shell\open\command" |
Reference:
https://www.huntress.com/blog/darkme-rat-abandons-exploits