Hackers Delivered DarkMe Trojan via Phishing Emails

A new malware campaign utilizes social engineering and forged files to compromise user machines.

Updated on Sept. 23, 2026 in Cybersecurity

Bold flat-color editorial illustration of a geometric server rack structure in navy and cream with a single deep red conduit line.
Hackers have launched a widespread phishing campaign deploying the DarkMe trojan, masquerading as legitimate software to exfiltrate data from compromised user systems. AI Illustration. Upload story photo >

Live Poll

Do you trust your ability to identify fake security software attached to emails?

Hackers have launched a campaign distributing the DarkMe remote access trojan through deceptive phishing emails. The malicious software mimics a product called Aegis Sentinel to bypass initial user suspicion.

Why it matters

Attackers have shifted toward social engineering tactics because these methods yield outcomes comparable to expensive zero-day exploits. This strategy allows them to compromise systems without the significant financial investment required for high-end vulnerabilities.

The malware infection chain utilizes three obfuscated loaders written in Visual Basic 6. To verify a genuine user machine, the trojan scans for 329 specific applications before injecting its payload into the legitimate Microsoft process clspack.exe.

The players

Microsoft

Microsoft is a multinational technology corporation that develops the Windows operating system and various software processes, including clspack.exe, which is targeted by the DarkMe malware.

Aegis Sentinel

Aegis Sentinel is the name of the product that the attackers have forged to create a sense of legitimacy for their malicious files.

The details

The attack begins with a phishing email containing a link to a file named image.pif, which poses as the Aegis Sentinel software. While researchers discovered a coding flaw in the malware's RC4 encryption, the trojan remains capable of effective data exfiltration via a newly identified command-and-control domain.

Timeline

  1. The campaign's use of a WinRAR zero-day flaw occurred in 2023.

  2. The group weaponized a Windows Defender SmartScreen zero-day in 2024.

  3. The current DarkMe malware campaign was active in 2026.

The Tech Race

This campaign follows the documented trend by prioritizing social engineering techniques over more complex, expensive exploit development. By utilizing deceptive tactics rather than zero-day vulnerabilities, the attackers maintain high success rates while minimizing their R&D costs.

Users should be wary of unexpected emails containing links to .pif files or attachments claiming to be Aegis Sentinel. Identifying these phishing attempts is critical, as the malware is designed to camouflage its activity by mimicking trusted background processes.

The takeaway

The discovery of a coding flaw in the DarkMe encryption implementation demonstrates the importance of deep technical analysis in stopping modern malware. Individuals should implement robust email filtering and avoid executing files from unverified digital sources to mitigate these risks.

Further reading

For more information on evolving digital threats, visit our Cybersecurity section.

Live Poll

Do you trust your ability to identify fake security software attached to emails?