New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data
ID: cf1c9a70-fe91-55f7-869b-45bbd08163b8
STIX ID: report--cf1c9a70-fe91-55f7-869b-45bbd08163b8
Feed Name: cybersecurityNews.com
Fortinet analysts identified a sophisticated fileless variant of the DarkCloud infostealer distributed through phishing RAR attachments that execute a JavaScript dropper; the malware extracts an encrypted .NET DLL embedded inside a JPEG and loads it directly into memory. It employs process hollowing and anti-sandbox checks (GetAsyncKeyState), persists by copying a JS to C:\Users\Public\Downloads\edriophthalma.js and creating an HKCU Run registry entry, and harvests saved credentials and payment card data from major browsers using direct SQL queries against browser databases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
