[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fI75wgzK7etA6tv3fLggHe0JwG7FCrGOcSgS5GHpewqI":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":28,"category":29,"article_tags":32},"359b6e32-37bd-4e6f-9327-80e018b24dee","Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign","zero-day-hackers-ditch-exploits-for-a-fake-image-file-in-new-darkme-campaign-1c4909","A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image. New research from Huntress details a 2026 campaign delivering DarkMe, a remote access trojan (RAT) historically linked to Water Hydra and also tracked as […] The post Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign appeared first on IT Security Guru.","A threat group, previously known for exploiting zero-day vulnerabilities in WinRAR and Windows, has shifted to a simpler attack vector. The new campaign, detailed by Huntress, uses email links leading to what appears to be an image file to deliver the DarkMe remote access trojan (RAT). This RAT has historical ties to the Water Hydra group.","Hackers use fake image file links to deliver DarkMe RAT in new campaign.",null,"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F09\u002F23\u002Fzero-day-hackers-ditch-exploits-for-a-fake-image-file-in-new-darkme-campaign\u002F?utm_source=rss&utm_medium=rss&utm_campaign=zero-day-hackers-ditch-exploits-for-a-fake-image-file-in-new-darkme-campaign","2026-09-23T10:52:39+00:00","2026-09-23T12:00:24.239697+00:00",8,[17,20,23,26],{"name":18,"type":19},"Water Hydra","threat_actor",{"name":21,"type":22},"DarkMe","campaign",{"name":24,"type":25},"WinRAR","product",{"name":27,"type":25},"Windows","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":28,"icon":11,"name":30,"slug":31},"Malware","malware",[33,38,43],{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":45,"icon":11,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49],{"type":31,"value":21,"context":50},"Remote Access Trojan (RAT) delivered in the campaign"]