Water Hydra, also known as DarkCasino, is a financially motivated cybercrime group active since at least 2021. The group has targeted financial-market participants, including forex and stock traders, banks, cryptocurrency platforms, and trading services, primarily to deploy the DarkMe remote-access trojan. Water Hydra is known for exploiting zero-day vulnerabilities to evade Windows security protections, including CVE-2023-38831 in WinRAR and CVE-2024-21412, a Windows Internet Shortcut security-feature bypass. Campaigns have used trader-themed lures distributed through phishing, trading forums, and messaging channels. Observed infection chains have included malicious shortcuts and executable files masquerading as benign documents or images, remote installer retrieval, multi-stage Visual Basic 6 loaders, COM-based execution through rundll32, process hollowing, and persistence through user-level startup mechanisms. DarkMe supports remote command execution, file operations, screenshot capture, security-product enumeration, and theft of cryptocurrency-wallet data. Activity attributed to the group has also employed PowerShell-based loaders, AMSI bypasses, fileless .NET assembly execution, scriptlets, and GitHub-hosted encrypted payloads. Water Hydra has been linked in reporting to the DarkMe malware lineage and, with lower confidence, to older Evilnum-associated development artifacts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
In late 2023 and early 2024, Water Hydra pivoted to CVE-2024-21412, a Defender SmartScreen bypass built on a shortcut-that-points-to-another-shortcut, staged over a WebDAV share behind a crafted Explorer view.
In 2023, Water Hydra weaponised the WinRAR extension-spoofing flaw CVE-2023-38831 as a zero day, dropping malicious archives on trading forums.
Zero-day zraniteľnosti CVE-2024-29988 a CVE-2024-26234 sú aktívne zneužívané. CVE-2024-29988 (CVSS skóre 8,8) Vysoko závažná zraniteľnosť CVE-2024-29988 umožňuje útočníkom obísť bezpečnostnú funkciu Windows SmartScreen a spustiť špeciálne pripravený škodlivý súbor. Chyba bola aktívne zneužívaná hackerskou skupinou Water Hydra.
63 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated DarkMe operations that historically targeted forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users. The described 2026 campaign shifted to scalable phishing against broader corporate users rather than using prior zero-day delivery chains.
Financially themed intrusion activity targeting forex traders and cryptocurrency users, using DarkMe RAT and QuasarRAT with GitHub-hosted multi-stage loaders. The content frames WaterHydra as still active in 2026 through an affiliate-linked operation and historical exploitation of trader-focused lures.
Financially motivated intrusion group tied to trader-focused campaigns, DarkMe RAT activity, and exploitation of CVE-2023-38831 and CVE-2024-21412. The report links current evilgrou-tech operations to this group through shared developer artifacts, infrastructure, tooling, and targeting.
Exploiting CVE-2024-21412 to bypass Microsoft Defender SmartScreen via malicious .url files and WebDAV shares in phishing activity targeting traders.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.