logo

DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation

ID: 04ae1b75-4c0b-5bd5-9b74-2287c20b1d29

STIX ID: report--04ae1b75-4c0b-5bd5-9b74-2287c20b1d29

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-08-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report details the DarkCloud Stealer, a sophisticated information-stealing malware campaign that employs multi-stage delivery (JavaScript downloaders, PowerShell, 7z/TAR archives), ConfuserEx-based .NET obfuscation, RC4/ AES/ Base64 encrypted payloads, and process hollowing into RegAsm.exe to evade detection; active command-and-control infrastructure and IoCs (e.g., 176.65.142.190 and filenames like holographies.exe) have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.