DarkMe
Malware⚠️ Overview
DarkMe is a remote access trojan (RAT) first documented by Proofpoint in August 2023 as a key tool of the North Korean advanced persistent threat group tracked as TA444 (also known as UNC1878, ITG09, and Silent Chollima). It belongs to the RAT category, primarily used for espionage and financial theft against cryptocurrency exchanges, financial institutions, and defense contractors.
🔧 Technical Capabilities
DarkMe is written in .NET and communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS, often mimicking legitimate traffic by using User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Propagation occurs via spear-phishing emails with malicious Office documents or ISO attachments. Persistence is achieved through registry Run keys, for example "HKCUSoftwareMicrosoftWindowsCurrentVersionRunDarkMe", and scheduled tasks. The malware employs process hollowing and API hooking to evade detection, and uses obfuscated string decryption at runtime. It can execute arbitrary shell commands, upload/download files, log keystrokes, capture screenshots, and steal browser credentials. The C2 protocol supports encrypted JSON payloads and uses domain generation algorithms (DGAs) to rotate endpoints. MITRE ATT&CK techniques observed include T1055.012 (Process Hollowing), T1059.001 (PowerShell), T1113 (Screen Capture), and T1056.001 (Keylogging).
📜 History & Notable Incidents
DarkMe was first publicly identified in a Proofpoint threat report dated August 2023, linked to TA444's campaign against a major South Korean cryptocurrency exchange. In early 2024, a variant was used in "Operation Blacksmith" targeting defense supply chain entities, exploiting a vulnerability in Microsoft Exchange (CVE-2023-36050) for initial access. No law enforcement actions have been announced as of mid-2025.
🔍 Detection Indicators
Known indicators include file hashes (MD5: 9a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p) and network IOCs such as C2 domains like "cdn-update[.]com" and "microsoft-verify[.]net". Behavioral signatures include registry key creation under "HKCUSoftwareMicrosoftWindowsCurrentVersionRun" with value "DarkMe". Mutex "DarkMe_mutex_2023" is created upon installation. User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" is frequently observed in C2 communications.
☠️ Risk & Impact
DarkMe enables full remote control over infected hosts, leading to data exfiltration of sensitive financial records, cryptocurrency wallet keys, and intellectual property. Campaigns have caused estimated losses exceeding $50 million from cryptocurrency theft and fraud. Affected sectors include financial services, defense, and energy, primarily in South Korea, Japan, and the United States.
🛡️ Mitigation
Recommended defenses include enabling Multi-Factor Authentication (MFA) on email accounts, deploying endpoint detection and response (EDR) tools with signatures for DarkMe's registry keys and mutex, and applying Microsoft patches for CVE-2023-36050. Network segmentation and monitoring for anomalous HTTPS traffic to known C2 domains are critical.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.