MalwareSep 23, 2026
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign
Hackers use fake image file links to deliver DarkMe RAT in new campaign.
Summary
A threat group, previously known for exploiting zero-day vulnerabilities in WinRAR and Windows, has shifted to a simpler attack vector. The new campaign, detailed by Huntress, uses email links leading to what appears to be an image file to deliver the DarkMe remote access trojan (RAT). This RAT has historical ties to the Water Hydra group.
Indicators of Compromise
- malware — DarkMe
Entities
Water Hydra (threat_actor)DarkMe (campaign)WinRAR (product)Windows (product)