Threat Advisory

DarkMe Malware Uses PIF to Launch Windows Installer

Threat: Vulnerability
Threat Actor Name: Water Hydra
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The MSI is wrapped using exemsi, a benign scaffolding that expands a Windows Cabinet archive file and runs a script. The script copies files into and registers a COM server under. The loader chain consists of three VB6 loaders, each calling a named export in the next, with the final stage hollowing out a signed Microsoft binary (a malicious executable) to run a VB6 stealer and RAT. The DarkMe malware has been observed targeting a wide range of users, including corporate employees, cryptocurrency traders, and online gamers.

It uses a variety of techniques to evade detection, including hiding behind Explorer and using a custom protocol handler to masquerade as a legitimate system process. The malware also includes a hardcoded port (7712) that presents a simple detection opportunity. To mitigate this threat, it is essential to monitor for suspicious activity related to msiexec, a built-in system utility, and a malicious executable imports, as well as signed Microsoft binaries running from rather than System32/SysWOW64.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The MSI is wrapped using exemsi, a benign scaffolding that expands a Windows Cabinet archive file and runs a script. The script copies files into and registers a COM server under. The loader chain consists of three VB6 loaders, each calling a named export in the next, with the final stage hollowing out a signed Microsoft binary (a malicious executable) to run a VB6 stealer and RAT. The DarkMe malware has been observed targeting a wide range of users, including corporate employees, cryptocurrency traders, and online gamers.

It uses a variety of techniques to evade detection, including hiding behind Explorer and using a custom protocol handler to masquerade as a legitimate system process. The malware also includes a hardcoded port (7712) that presents a simple detection opportunity. To mitigate this threat, it is essential to monitor for suspicious activity related to msiexec, a built-in system utility, and a malicious executable imports, as well as signed Microsoft binaries running from rather than System32/SysWOW64.[emaillocker id="1283"]

:A zero-day flaw in WinRAR, was weaponized by Water Hydra to deliver the DarkMe malware. The exploit dropped malicious archives on trading forums, targeting forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users. :A Defender SmartScreen bypass built on a shortcut-that-points-to-another-shortcut (yes, this was a thing), staged over a WebDAV share behind a crafted Explorer view.

RECOMMENDATION:

We recommend you to update DarkMe to version 11.0.53.0.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.005 Command and Scripting Interpreter Visual Basic
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu