DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation
ID: 04ae1b75-4c0b-5bd5-9b74-2287c20b1d29
STIX ID: report--04ae1b75-4c0b-5bd5-9b74-2287c20b1d29
Feed Name: cybersecurityNews.com
Threat Score
The report details the DarkCloud Stealer, a sophisticated information-stealing malware campaign that employs multi-stage delivery (JavaScript downloaders, PowerShell, 7z/TAR archives), ConfuserEx-based .NET obfuscation, RC4/ AES/ Base64 encrypted payloads, and process hollowing into RegAsm.exe to evade detection; active command-and-control infrastructure and IoCs (e.g., 176.65.142.190 and filenames like holographies.exe) have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
