Water Hydra, also widely tracked as DarkCasino, is a financially motivated threat actor focused primarily on financial-market participants, including forex traders, stock traders, banks, cryptocurrency platforms, trading services, gambling sites, and casinos. The group has been active since at least 2021 and is notable for combining social-engineering-heavy delivery with rapid adoption of exploit chains and commodity as well as custom malware. Water Hydra is best known for exploiting CVE-2024-21412, a Windows Internet Shortcut and SmartScreen bypass vulnerability, in campaigns targeting traders and delivering the DarkMe remote access trojan. The group also previously leveraged the WinRAR zero-day CVE-2023-38831 in trader-focused intrusion activity. Reporting has characterized the actor as a cybercrime or financially motivated APT due to its sustained operations, exploit usage, and disciplined malware development. DarkMe is the signature malware most consistently associated with Water Hydra. It has been linked to multi-stage infection chains using malicious shortcuts, script-based loaders, WebDAV-hosted payload delivery, MSI-based installers, and fileless .NET execution. Observed tradecraft includes phishing lures themed around financial documents or trading activity; abuse of Windows Explorer and remote file handling to reduce user suspicion; AMSI bypasses; encrypted payload staging; persistence through autorun mechanisms and startup items; and command-and-control over custom TCP or TLS-protected channels. Water Hydra has also been observed using QuasarRAT in some operations, indicating flexibility in tooling beyond its core DarkMe ecosystem. Attribution links connect Water Hydra with DarkCasino at high confidence, and some reporting further ties parts of its tooling lineage to Evilnum through shared developer artifacts and overlapping malware-development fingerprints. A 2026 operation using the GitHub persona "evilgrou-tech" was assessed with high confidence as part of the WaterHydra/DarkCasino lineage, likely representing a lower-tier operator or affiliate using inherited DarkMe tooling and older builder infrastructure. That activity retained the group’s established focus on forex and trading victims while adding GitHub-based staging, PowerShell and script loaders, AMSI bypasses, AES-encrypted payloads, and persistence mechanisms consistent with prior Water Hydra tradecraft. The actor’s operational profile reflects a blend of targeted financial victimology, exploit-enabled initial access, and malware delivery optimized to evade Windows trust and warning mechanisms. Water Hydra is therefore best understood as a financially motivated intrusion set with advanced capabilities, strong association with DarkMe, and a demonstrated pattern of exploiting newly disclosed or zero-day vulnerabilities to compromise trading-focused targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
the exploitation of a zero-day vulnerability (CVE-2024–21412). This vulnerability allowed the bypass of Microsoft Defender SmartScreen through malicious .url files and WebDAV shares.
2023-04 WaterHydra exploits CVE-2023-38831 (WinRAR zero-day), 130+ traders infected
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially themed intrusion activity targeting forex traders and cryptocurrency users, using DarkMe RAT and QuasarRAT with GitHub-hosted multi-stage loaders. The content frames WaterHydra as still active in 2026 through an affiliate-linked operation and historical exploitation of trader-focused lures.
Financially motivated intrusion group tied to trader-focused campaigns, DarkMe RAT activity, and exploitation of CVE-2023-38831 and CVE-2024-21412. The report links current evilgrou-tech operations to this group through shared developer artifacts, infrastructure, tooling, and targeting.
Exploiting CVE-2024-21412 to bypass Microsoft Defender SmartScreen via malicious .url files and WebDAV shares in phishing activity targeting traders.
Attributed with exploiting CVE-2024-21412 to bypass Windows SmartScreen using malicious internet shortcuts disguised as JPEGs, and previously leveraging WinRAR zero-days to deploy DarkMe.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.