Skip to content

Sam's News โ€” email-security โ€” 2026-09-29

Email Security

6 DarkMe RAT shifts to simple phishing emails instead of zero-day exploits

DarkMe, a remote access trojan previously used to target financial traders and cryptocurrency users, has been spotted in new attacks that rely on straightforward phishing emails rather than zero-day exploits. The malware disguises itself as an image file (.pif executable) and targets everyday corporate users, not just niche traders, marking a significant shift in attack strategy.

  • DarkMe uses .pif file disguised as PNG to trick users into executing malware via email attachment or link
  • Malware performs inverted sandbox check against 329 applications (gaming clients, crypto wallets, password managers, browsers) to confirm human use before deploying payload
  • Threat group may be Spanish-based based on DLL localization properties; financially motivated but also targets children for gaming credentials
  • Attack represents shift from sophisticated zero-day exploits to low-cost phishing, broadening targets from niche forex traders to corporate users

Sources: Help Net Security AI Web Searched