chiprook
← Security
SecuritySeptember 23, 2026, 20:24

DarkMe RAT returns with plain phishing instead of zero-days

The DarkMe trojan, previously linked to attacks on traders and crypto users, is active again. Attackers now send emails with a link posing as a PNG that downloads image.pif, a Windows executable, then a loader chain checks for 329 applications and steals crypto wallets.

DarkMe RAT returns with plain phishing instead of zero-days
#DarkMe#Huntress#Windows
Read next
Security

UAE and Saudi Arabia Absorb Half of Gulf Cyberattacks

Security

Hundreds of Leaked GitHub App Keys Still Authenticate

Security

FomoPeek crypto app in App Store hid iOS kernel exploits to steal wallet keys

Security

Attackers Poison ChatGPT, Gemini and Google AI Overview Answers