A new DarkMe remote-access Trojan campaign has shifted from the exploit-led delivery associated with Water Hydra to straightforward phishing. Lures disguised as image links served executable .PIF files, which launched a remote MSI installer and a multistage Visual Basic 6 loader chain. The chain registers a COM object and invokes it through rundll32.exe /sta {CLSID}, checks for sandbox-like processes, creates persistence through a custom Locked:// URI handler, and process-hollows the signed Microsoft clspack.exe binary.
The final payload combines remote-access and infostealing functions: it can collect cryptocurrency-wallet data, take screenshots, enumerate installed antivirus products, manipulate files, and run commands. It communicates over custom TCP command-and-control on port 7712; observed infrastructure included thatawful[.]boutique resolving to 67.43.50[.]11:7712. Organizations should block the identified infrastructure, investigate .PIF downloads and suspicious remote MSI execution, and hunt for the rundll32.exe /sta COM-launch pattern and unauthorized Locked:// registry protocol handlers.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The final DarkMe payload was configured to decrypt the C2 domain thatawful[.]boutique and communicate over hardcoded TCP port 7712; the observed endpoint was 67.43.50[.]11:7712. It could steal cryptocurrency-wallet data, capture screenshots, enumerate antivirus products, manipulate files, and execute commands.
A DarkMe campaign used phishing links masquerading as image files rather than prior zero-day delivery methods; one link delivered image.pif, which invoked msiexec to retrieve propi.msi. The multi-stage VB6 loader chain registered a COM object, established Locked:// registry persistence, and hollowed Microsoft-signed clspack.exe to run the final RAT/stealer.
Attackers distributed Efimer in a June email campaign impersonating lawyers and falsely alleging trademark infringement. Attached archives ultimately delivered the Requirement.wsf installer, which established persistence and downloaded a Tor proxy for C2 communication.
Trend Micro reported that Water Hydra targeted traders using CVE-2024-21412, a Microsoft Defender SmartScreen bypass zero-day. DarkMe had previously been associated with Water Hydra, subject to attribution caveats.
Kaspersky assessed that early Efimer versions likely emerged around October 2024 and initially spread through compromised WordPress websites. The malware functioned as a ClipBanker and cryptocurrency stealer, using Tor for command-and-control communications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourcetrendmicro.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.