Skip to content
DarkMe RAT Evolves: From Exploits to Social Engineering Attacks

DarkMe RAT Evolves: From Exploits to Social Engineering Attacks

First seen 23 Sep 2026, 00:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 01:59 UTC
  • DarkMe RAT now uses social engineering instead of exploits for distribution.
  • Two incidents involving DarkMe were reported on August 31, 2026.
  • The malware collects sensitive host information and employs novel persistence techniques.

The DarkMe malware, a Visual Basic 6 (VB6) remote access trojan (RAT), was identified in two incidents affecting different organizations on August 31, 2026. Previously attributed to the APT group Evilnum, DarkMe has transitioned from using zero-day exploits (CVE-2023-38831 and CVE-2024-21412) to relying on social engineering tactics to distribute its payload via .pif files. This shift reflects a broader trend in cyberattacks, where adversaries favor low-skill, high-volume methods over complex technical exploits. The recent campaign also introduced novel techniques, such as a nonstandard protocol handler for persistence. The malware collects sensitive host information and communicates with its command and control (C&C) server. The evolution of DarkMe highlights the need for defenders to adapt their strategies against increasingly sophisticated social engineering tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-08-23
CVE-2023-38831 published
A zero-day vulnerability in WinRAR was disclosed, which DarkMe previously exploited.
Huntress
2024-02-13
CVE-2024-21412 published
A vulnerability in Windows Defender SmartScreen was disclosed, also exploited by DarkMe.
Huntress
2026-08-31
DarkMe incidents reported
Huntress identified two separate incidents involving DarkMe affecting different organizations.
Huntress
2026-09-22
Huntress article published
Huntress published findings on DarkMe's evolution and its current attack methods.
Huntress
2026-09-23
NSFOCUS article published
NSFOCUS provided an in-depth analysis of DarkMe and its connection to Evilnum's operations.
nsfocusglobal.com

More articles in this cluster (5)

Following this threat?

Track Water Hydra, Evilnum and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed