nsfocusglobal.com DarkMe RAT Evolves: From Exploits to Social Engineering Attacks
Article Content
- •DarkMe RAT now uses social engineering instead of exploits for distribution.
- •Two incidents involving DarkMe were reported on August 31, 2026.
- •The malware collects sensitive host information and employs novel persistence techniques.
The DarkMe malware, a Visual Basic 6 (VB6) remote access trojan (RAT), was identified in two incidents affecting different organizations on August 31, 2026. Previously attributed to the APT group Evilnum, DarkMe has transitioned from using zero-day exploits (CVE-2023-38831 and CVE-2024-21412) to relying on social engineering tactics to distribute its payload via .pif files. This shift reflects a broader trend in cyberattacks, where adversaries favor low-skill, high-volume methods over complex technical exploits. The recent campaign also introduced novel techniques, such as a nonstandard protocol handler for persistence. The malware collects sensitive host information and communicates with its command and control (C&C) server. The evolution of DarkMe highlights the need for defenders to adapt their strategies against increasingly sophisticated social engineering tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Water Hydra, Evilnum and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spearphishing Campaigns Exploit Malicious Links for User Execution Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information, including credentials. Notable threat actors such as APT28, APT29, and FIN7 have been identified as…
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks 89