Help Net Security·3 min read

days for plain phishing emails

Z
Zeljka Zorz
days for plain phishing emails
Dive DeeperCreate a free account to unlock

DarkMe RAT trades zero-days for plain phishing emails DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again.

This time around, its distribution has been simplified: instead of leveraging zero-day exploits , attackers are betting on a simple email to convince targets to run it on their machine:

The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress)

The link supposedly points to a PNG file, but clicking on it triggers the download of image.pif , a Windows executable.

Huntress, a cybersecurity company that pairs its own security software with a 24/7 human-led SOC, says that the same binary was delivered to two of its customers’ envrionments.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in