The MSI is wrapped using exemsi, a benign scaffolding that expands a Windows Cabinet archive file and runs a script. The script copies files into and registers a COM server under. The loader chain consists of three VB6 loaders, each calling a named export in the next, with the final stage hollowing out a signed Microsoft binary (a malicious executable) to run a VB6 stealer and RAT. The DarkMe malware has been observed targeting a wide range of users, including corporate employees, cryptocurrency traders, and online gamers.
It uses a variety of techniques to evade detection, including hiding behind Explorer and using a custom protocol handler to masquerade as a legitimate system process. The malware also includes a hardcoded port (7712) that presents a simple detection opportunity. To mitigate this threat, it is essential to monitor for suspicious activity related to msiexec, a built-in system utility, and a malicious executable imports, as well as signed Microsoft binaries running from rather than System32/SysWOW64.[/subscribe_to_unlock_form]
The MSI is wrapped using exemsi, a benign scaffolding that expands a Windows Cabinet archive file and runs a script. The script copies files into and registers a COM server under. The loader chain consists of three VB6 loaders, each calling a named export in the next, with the final stage hollowing out a signed Microsoft binary (a malicious executable) to run a VB6 stealer and RAT. The DarkMe malware has been observed targeting a wide range of users, including corporate employees, cryptocurrency traders, and online gamers.
It uses a variety of techniques to evade detection, including hiding behind Explorer and using a custom protocol handler to masquerade as a legitimate system process. The malware also includes a hardcoded port (7712) that presents a simple detection opportunity. To mitigate this threat, it is essential to monitor for suspicious activity related to msiexec, a built-in system utility, and a malicious executable imports, as well as signed Microsoft binaries running from rather than System32/SysWOW64.[emaillocker id="1283"]
:A zero-day flaw in WinRAR, was weaponized by Water Hydra to deliver the DarkMe malware. The exploit dropped malicious archives on trading forums, targeting forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users. :A Defender SmartScreen bypass built on a shortcut-that-points-to-another-shortcut (yes, this was a thing), staged over a WebDAV share behind a crafted Explorer view.
We recommend you to update DarkMe to version 11.0.53.0.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.005 | Command and Scripting Interpreter | Visual Basic |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]