DarkMe is a Visual Basic 6-based Windows remote-access trojan with information-stealing and spyware capabilities. It has been associated in multiple campaigns with the financially motivated Water Hydra, also known as DarkCasino, and has historical reporting links to Evilnum. DarkMe campaigns have focused heavily on foreign-exchange and financial-market traders, including distribution through trader-focused forums, messaging channels, phishing, and file-sharing services.
DarkMe has been delivered through crafted archives exploiting WinRAR CVE-2023-38831 and through malicious Internet Shortcut files exploiting the Windows SmartScreen bypass CVE-2024-21412. Later activity used phishing links masquerading as image content to deliver executable PIF files, followed by remote installer packages and a multi-stage loader chain.
Observed loader chains use obfuscated VB6 components, COM-based execution, environment checks intended to identify sandboxes or lightly used systems, registry-based logon persistence, and process hollowing into a legitimate Microsoft-signed executable. The DarkMe payload communicates over custom TCP command-and-control and supports arbitrary command execution, file operations, screenshot capture, security-product enumeration, and collection of cryptocurrency-wallet data. Its payload protection has used a flawed RC4-like routine rather than correctly implemented RC4 encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A 2026 phishing campaign delivers DarkMe through a disguised image.pif file; it uses three obfuscated Visual Basic 6 loaders, checks for 329 applications to evade sandboxing, and injects its final payload into clspack.exe.
A 2026 phishing campaign delivers DarkMe through a disguised image.pif file; it uses three obfuscated Visual Basic 6 loaders, checks for 329 applications to evade sandboxing, and injects its final payload into clspack.exe.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A 2026 phishing campaign delivers DarkMe through a disguised image.pif file; it uses three obfuscated Visual Basic 6 loaders, checks for 329 applications to evade sandboxing, and injects its final payload into clspack.exe.
DarkMe is a VB6 stealer and RAT delivered through a phishing link to a PIF file masquerading as an image, followed by a remote MSI, COM-based DLL loaders, and process hollowing into clspack.exe.
The group's DarkMe VB6 builder -- compiled in May 2022 -- is still producing active malware in March 2026, and their C2 at 91.124.98.29:2626 was confirmed live at time of investigation.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The Sentinel variant is delivered via a 779KB PowerShell wrapper ( sentinel.ps1 ) that: Requests admin elevation via UAC prompt Decompresses a GZip-compressed .NET PE from an embedded byte array Writes to SubDir\Sys.exe and registers as "Runtime Broker" in HKCU\Run
“In 2023, Water Hydra weaponised the WinRAR extension-spoofing flaw CVE-2023-38831 as a zero day ... In late 2023 and early 2024, Water Hydra pivoted to CVE-2024-21412, a Defender SmartScreen bypass.”
"... abused this bypass flaw to trick financial traders into ultimately infecting their PCs ... seeded in forex trading forums and stock trading Telegram channels."
“Only then does it inject the final payload into clspack.exe, a legitimate, digitally signed Microsoft program”
“stage 3 hollows out clspack.exe, a legitimate Microsoft-signed binary.”
“The malware passes through three heavily obfuscated loaders written in Visual Basic 6” and “DarkMe’s payload is protected with what was intended to be RC4 encryption.”
“image.pif, a Windows program in disguise” and “forged details suggesting it belongs to a security product named ‘Aegis Sentinel’.”
“Only then does it inject the final payload into clspack.exe, a legitimate, digitally signed Microsoft program”
“stage 3 hollows out clspack.exe, a legitimate Microsoft-signed binary.”
MITRE ATT&CK T1140 — Deobfuscate/Decode (8 crypto schemes, 2-layer AES nesting)
“The PIF's only job is to invoke the Microsoft installer, msiexec, to download and execute an .msi installer file.”
“the gate walks the live process list, making it a point-in-time test rather than a survey of what the host has installed.”
“The first job of Finalized.dll:Calculation is building a host-profile report from seven Environ$() calls ... alongside a broader survey of hardware, services, policy, display and locale keys.”
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DarkMe is a remote-access trojan historically linked to Water Hydra/DarkCasino. In this campaign, it is delivered through phishing rather than an exploit, conducts extensive anti-analysis checks, injects into a signed Microsoft process, and is characterized as shifting toward conventional information-stealing activity.
A Visual Basic 6 remote-access trojan and information stealer. This campaign steals cryptocurrency-wallet data, captures screenshots, enumerates installed antivirus, manipulates files, and executes arbitrary commands through a custom TCP C2 channel. It employs a multi-stage loader chain, a user-process anti-sandbox gate, registry-based persistence via a custom Locked:// URL handler, and RunPE process hollowing into a signed Microsoft binary.
DarkMe is a RAT used by the same operator across historical infrastructure from 2023 through 2026. The report describes DarkMe VB6 payloads delivered through layered AES-wrapped loaders, COM scriptlets, PowerShell, and JavaScript, with multiple persistence mechanisms and evolving C2 infrastructure.
A Visual Basic 6 remote access trojan built with a compile-once, patch-config builder model. It supports command execution, directory listing, file operations, ZIP archive creation, suspected screenshot capture, persistence via Run/RunOnce and COM registration, and custom TCP/UDP C2 communications using reversed UTF-16LE command strings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.