days for plain phishing emails

DarkMe RAT trades zero-days for plain phishing emails DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again.
This time around, its distribution has been simplified: instead of leveraging zero-day exploits , attackers are betting on a simple email to convince targets to run it on their machine:
The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress)
The link supposedly points to a PNG file, but clicking on it triggers the download of image.pif , a Windows executable.
Huntress, a cybersecurity company that pairs its own security software with a 24/7 human-led SOC, says that the same binary was delivered to two of its customers’ envrionments.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in