logo

DarkCloud Infostealer Emerges as Major Threat With Scalable Credential Theft Targeting Enterprises

ID: 709e0363-dd0f-566d-b37b-8ef8a5a1549e

STIX ID: report--709e0363-dd0f-566d-b37b-8ef8a5a1549e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

DarkCloud is a commercial credential‑harvesting infostealer sold on Telegram and a clearnet storefront that targets major browsers, email clients, FTP/VPN clients and contact lists to harvest credentials, cookies and payment data; it stages stolen data under %APPDATA%\Microsoft\Windows\Templates and exfiltrates via SMTP, FTP, Telegram or HTTP. The malware is written using VB6 runtime components compiled into native code to evade detection and uses a deterministic VB PRNG-based string obfuscation to frustrate analysis; Flashpoint links it to an earlier BluStealer/A310LoggerStealer project. Recommended mitigations include strict email attachment filtering, monitoring for abnormal exfiltration, credential rotation, enterprise password management, and EDR coverage for legacy VB6 runtimes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.