DarkMe, a remote access trojan and info-stealer, has been spotted again after previously being associated with a threat group that targeted financial market traders and cryptocurrency users. According to Help Net Security, the latest campaign simplifies distribution by relying on ordinary phishing emails rather than more complex exploit chains.
The shift is notable because DarkMe's past operations leveraged zero-day vulnerabilities to reach its targets. Now, the malware is being delivered through straightforward phishing lures, suggesting the group has adapted its tactics to lower operational overhead while still aiming at corporate and individual victims.
While the source does not provide specific details on the phishing messages or the current target set, it makes clear that the move away from zero-days is a deliberate change in strategy. This development underscores how even advanced threat actors are increasingly turning to simpler, cost-effective methods of initial access.