logo

DarkCloud – An Advanced Stealer Malware Selling Via Telegram To Steal Data From Windows

ID: f070cb82-b829-5220-bd65-0495ccc25bc6

STIX ID: report--f070cb82-b829-5220-bd65-0495ccc25bc6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

DarkCloud is a Windows-focused stealer first observed in 2022 that uses multi-stage, obfuscated loaders (including Base64 + TripleDES components) and injects into legitimate processes (e.g., svchost.exe, MSBuild) to stealthily harvest browser data, passwords, email/FTP credentials, cryptocurrency wallets, screenshots, and keystrokes; it is widely distributed via phishing campaigns (targeting HR), malvertising, watering holes, and is sometimes deployed alongside other malware, with data exfiltration performed through Telegram channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.