International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 23 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

by Guru Writer
September 23, 2026
in News
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign
Share on FacebookShare on Twitter

A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image.

New research from Huntress details a 2026 campaign delivering DarkMe, a remote access trojan (RAT) historically linked to Water Hydra and also tracked as DarkCasino. The group made headlines in 2023 and 2024 for weaponising two zero-days, CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen, in attacks on foreign exchange traders.

This time, no exploit is involved. According to Huntress, victims receive a phishing email containing a link that looks like it serves a picture but instead downloads a file called image.pif, a Windows program in disguise. The file carries forged details suggesting it belongs to a security product named “Aegis Sentinel”. Double-clicking it quietly pulls down a Windows installer package from a remote server and sets the infection in motion.

Checking for a human at the keyboard

What follows is a multi-stage chain designed to stay out of sight. The malware passes through three heavily obfuscated loaders written in Visual Basic 6, then checks the machine for 329 different applications to confirm it is running on a genuine, in-use computer rather than a researcher’s sandbox. Only then does it inject the final payload into clspack.exe, a legitimate, digitally signed Microsoft program, so that its activity appears to come from a trusted process.

Huntress characterises the result as a shift for DarkMe from an APT-linked tool to a more conventional information stealer.

A broken cipher, previously misread

The researchers also uncovered a flaw in the attackers’ own code. DarkMe’s payload is protected with what was intended to be RC4 encryption, but the implementation skips a key step in setting up the cipher. As a result, the scrambling collapses into a predictable pattern after just a few bytes. Huntress notes that earlier public reporting had described this routine as simple XOR encoding, and its analysis corrects that picture.

The team has also identified a new encryption key and a new command-and-control domain used in the campaign, and has published detection rules, indicators of compromise and remediation guidance alongside the research.

Back to basics

The findings echo a broader trend of well-resourced attackers favouring social engineering over costly vulnerabilities where it delivers the same outcome. For defenders, Huntress’s guidance points to the human side of the attack chain as much as the technical one: treating unusual file types arriving by email with suspicion, and monitoring for legitimate Windows tools being used to fetch and run software from the internet.

ShareTweet
Previous Post

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

Recent News

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

September 23, 2026
CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

September 23, 2026
network segmentation

Only 13% of OT Network Segments Keep Operational Technology Isolated

September 22, 2026
agentic security platform

Salt Security adds native AI detection and response to agentic security platform

September 22, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol