Skip to content

Security2 publishers3 min readPublished

DarkMe's operators swapped two zero-days for a .pif file Windows executes on a double-click

Huntress found the same one-megabyte PIF in two customer environments, pulled down by a link that promised a PNG. Everything after it is the 2024 DarkMe chain, down to the rundll32 /sta GUID from that campaign.

The Watch · Security desk

Photograph accompanying DarkMe's operators swapped two zero-days for a .pif file Windows executes on a double-click
Photo: huntress.com

What happened

  • A phishing email linked to image.png on readonline365, but the webserver returned image.pif, a Windows executable, when the target clicked.
  • Huntress saw the identical one-megabyte PE32+ file land in two customer environments, where users double-clicked it without realising it was a program.
  • The PIF did one thing: it called msiexec to pull propi.msi from onlineview365 over HTTPS with /quiet and /norestart.
  • The final stage starts with rundll32.exe /sta on the same GUID Huntress observed in the 2024 campaign, a string the company recommends for detection and hunting.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The user has nothing to inspect: the properties sheet calls the file a shortcut to an MS-DOS program, so the block has to come at the mail gateway or from msiexec's behaviour on the host.
  • decision Teams that cannot filter .pif have a second gate available, since Huntress says an MSI fetched over HTTPS with /quiet from the root of an empty domain is rare in most environments.
  • exposure Brandt puts children in scope alongside corporate users, with Robux and game registration keys as loot, so home machines reached by the same malspam are targets.
  • contradiction Trend Micro and SonicWall tied this malware to Water Hydra, while Huntress cannot confirm who ran this campaign and points to Spanish localisation in the compiled DLLs, so the 2024 chain supports detection without supporting a name.

Renamed with an .exe extension, the file's Details tab showed forged metadata implying it was a component of a security product called Aegis Sentinel, which it has nothing to do with [12]. As delivered, its properties sheet described it as a "Shortcut to MS-DOS program" [11]. Huntress states the behaviour plainly: "Modern Windows systems execute .pif files as a program, regardless of what the extension implies (or what the icon shows)" [10]. "The users simply double-clicked and downloaded the file, not realising what it was," the company wrote [9].

Before DarkMe deploys, a loader chain inventories installed software: Slack, Discord, Zoom, WhatsApp, password managers, trading terminals, online poker clients, crypto wallets, VPN clients, game launchers, Spotify, browsers, PDF readers and OEM peripheral support utilities [20]. "Execution stops when none of the 329 are found. This is not a target list; it is an inverted sandbox check," the Huntress analysts wrote [21]. The peripheral utilities explain the logic: "Gaming-mouse configuration utilities and RGB lighting daemons hold nothing of value, but they do prove that a human being uses this computer," they wrote [22].

The MSI the PIF fetched was built with the exemsi MSI Wrapper, version 11.0.53.0, packaged under the cover name "PrinterFind Softwares", with a creation date of January 11, 2024 [15]. That date falls inside the late 2023 and early 2024 window when Water Hydra was running CVE-2024-21412, the Defender SmartScreen bypass staged over a WebDAV share [5][30]. The installer expands files.cab into %AppData%\ComponentsFolder\ and runs prnfig.wsf [16]. The script copies clspack.exe on its own into %AppData%\Microsoft\, staging the hollowing target [17]. It then rewrites a registry template, imports it, and hands off with rundll32 /sta [18]. Persistence comes from registry values, and the final payload is DarkMe, a Visual Basic 6 RAT and infostealer that goes after crypto wallets and can take screenshots [23][1].

Andrew Brandt, Principal Threat Intelligence Incident Commander at Huntress, told Help Net Security the company cannot confirm that Water Hydra, also called DarkCasino, ran this campaign [24]. "We do have some clues about the malware's possible origins. For example, the Spanish localization property in the compiled DLLs suggests that the developer may be a Spanish national or living in Spain," he said [25]. On motive, he said the activity "appears to be financially driven, though the actors also seem willing to target children for things like Roblox Robux or Steam and Epic Games registration keys" [26]. Huntress does not know whether DarkMe is sold as a service [27].

Two zero-days preceded this tradecraft: CVE-2023-38831, the WinRAR extension-spoofing flaw Water Hydra weaponised in 2023 against trading forums, and CVE-2024-21412 [4][5]. This campaign used neither, and no exploit at all [6][31]. "In 2026, users are still clicking links in unsolicited emails. As long as these old-school phishing tactics keep working, adversaries have no reason to burn expensive exploits," Brandt and colleague James Northey wrote [28]. The write-ups do not address whether either affected environment's mail or endpoint policy blocked .pif [33]. Huntress published indicators of compromise with containment and cleanup guidance [32].

What to watch

  • Whether Huntress or another vendor links this PIF delivery to Water Hydra infrastructure, not just to shared code.
  • Whether DarkMe turns up in campaigns run by unrelated crews, which would answer the as-a-service question.
  • Whether the operator rotates off .pif to another legacy executable extension once gateways start blocking it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories