logo

New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data

ID: cf1c9a70-fe91-55f7-869b-45bbd08163b8

STIX ID: report--cf1c9a70-fe91-55f7-869b-45bbd08163b8

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-08-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Fortinet analysts identified a sophisticated fileless variant of the DarkCloud infostealer distributed through phishing RAR attachments that execute a JavaScript dropper; the malware extracts an encrypted .NET DLL embedded inside a JPEG and loads it directly into memory. It employs process hollowing and anti-sandbox checks (GetAsyncKeyState), persists by copying a JS to C:\Users\Public\Downloads\edriophthalma.js and creating an HKCU Run registry entry, and harvests saved credentials and payment card data from major browsers using direct SQL queries against browser databases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.