DarkCloud – An Advanced Stealer Malware Selling Via Telegram To Steal Data From Windows
ID: f070cb82-b829-5220-bd65-0495ccc25bc6
STIX ID: report--f070cb82-b829-5220-bd65-0495ccc25bc6
Feed Name: cybersecurityNews.com
DarkCloud is a Windows-focused stealer first observed in 2022 that uses multi-stage, obfuscated loaders (including Base64 + TripleDES components) and injects into legitimate processes (e.g., svchost.exe, MSBuild) to stealthily harvest browser data, passwords, email/FTP credentials, cryptocurrency wallets, screenshots, and keystrokes; it is widely distributed via phishing campaigns (targeting HR), malvertising, watering holes, and is sometimes deployed alongside other malware, with data exfiltration performed through Telegram channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
