DarkMe RAT returns with plain phishing instead of zero-days
The DarkMe trojan, previously linked to attacks on traders and crypto users, is active again. Attackers now send emails with a link posing as a PNG that downloads image.pif, a Windows executable, then a loader chain checks for 329 applications and steals crypto wallets.
- The link delivers image.pif, a Windows executable disguised as an image
- The loader checks for 329 apps, from Slack and Zoom to crypto wallets and game utilities
- Execution stops if none of the 329 applications are found
- The final rundll32.exe command matches the 2024 campaign
Read next
Security