logo

DarkCloud Stealer Malware Selling on Telegram to Exploit Windows Users

ID: 34b1d5ef-9278-5607-97f9-ea345bf9bad2

STIX ID: report--34b1d5ef-9278-5607-97f9-ea345bf9bad2

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

The report details DarkCloud Stealer, an active Windows-targeting information-stealing malware distributed via phishing, malvertising, and Telegram sales channels since 2022; it describes multi-stage execution (loaders, in-memory injection, persistence), modular capabilities (credential and system data exfiltration, keylogging, screenshots), evasion techniques (obfuscation, Base64/TripleDES), and urges detection of persistence artifacts and improved endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.