WaterHydra
WaterHydra, also referred to in the provided content as DarkCasino and linked to Evilnum lineage, is described as a financially motivated threat group. The content attributes a 2026 GitHub-based operation run under the handle "evilgrou-tech" to the WaterHydra/DarkCasino APT group with high confidence, and states the group was behind exploitation of CVE-2024-21412 (Windows SmartScreen zero-day) and CVE-2023-38831 (WinRAR zero-day). The reporting ties together Evilnum, DarkCasino, WaterHydra, and the 2026 activity through a shared VB6 developer workspace path, C:\Users\Administrator\Desktop\vaeeva\shellrundll.tlb, found in a 2022 Evilnum-linked DLL and a 2024 WaterHydra payload. The content states DarkMe RAT is the signature malware of the WaterHydra/DarkCasino group. Based on the provided reporting, WaterHydra targeted forex traders and financial trading platforms, with additional 2026 targeting noted against forex traders in Italy and cryptocurrency users associated with "Pumpfun." Tooling used in the attributed operation included DarkMe RAT written in VB6 and QuasarRAT v1.4.1.0 in .NET; a QuasarRAT "Sentinel" variant and a Quakbot LNK sample were also associated with the same infrastructure in the 2026 reporting. DarkMe samples shared consistent builder characteristics across 2023-2026, including a common VB6 imphash, and the report states the actor continued using an older DarkMe builder compiled in May 2022. The content also notes that WaterHydra removed some attribution artifacts between 2022 and 2024, including Italian variable names and the "DarkMe" mutex string, but left the embedded type library path. The described tradecraft included forex-themed lures; PowerShell and script-based loaders; AMSI bypasses; AES-encrypted payload staging from GitHub repositories; fileless .NET assembly loading; regsvr32 COM scriptlets; mshta execution; and persistence via registry Run/RunOnce keys, startup shortcuts, and HTA files. DarkMe communications used custom TCP over a SOCKET_WINDOW class, and QuasarRAT communications used TLS 1.2 to 91.124.98.29:2626 in the 2026 operation. The content further states that the 2026 operator "evilgrou-tech" was likely a lower-tier WaterHydra operator or affiliate using inherited tooling and an older, less sanitized DarkMe builder. Known names and linked aliases/sub-groups directly mentioned in the content are WaterHydra, DarkCasino, and Evilnum lineage; the 2026 operator handle associated with the group is "evilgrou-tech."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Financial Services
Where they target
Geographies tied to known operations.
- 🇮🇹 Italy
Tradecraft
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
2023-04 WaterHydra exploits CVE-2023-38831 (WinRAR zero-day), 130+ traders infected
WaterHydra/DarkCasino APT group -- the financially-motivated crew behind CVE-2024-21412 (Windows SmartScreen zero-day)... 2023-12-31 WaterHydra exploits CVE-2024-21412 (SmartScreen 0-day) ... 2024-02-13 Microsoft patches CVE-2024-21412
Observables
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially themed intrusion activity targeting forex traders and cryptocurrency users, using DarkMe RAT and QuasarRAT with GitHub-hosted multi-stage loaders. The content frames WaterHydra as still active in 2026 through an affiliate-linked operation and historical exploitation of trader-focused lures.
Financially motivated intrusion group tied to trader-focused campaigns, DarkMe RAT activity, and exploitation of CVE-2023-38831 and CVE-2024-21412. The report links current evilgrou-tech operations to this group through shared developer artifacts, infrastructure, tooling, and targeting.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.