DarkCloud Stealer Malware Selling on Telegram to Exploit Windows Users
ID: 34b1d5ef-9278-5607-97f9-ea345bf9bad2
STIX ID: report--34b1d5ef-9278-5607-97f9-ea345bf9bad2
Feed Name: Cyber Press
Threat Score
The report details DarkCloud Stealer, an active Windows-targeting information-stealing malware distributed via phishing, malvertising, and Telegram sales channels since 2022; it describes multi-stage execution (loaders, in-memory injection, persistence), modular capabilities (credential and system data exfiltration, keylogging, screenshots), evasion techniques (obfuscation, Base64/TripleDES), and urges detection of persistence artifacts and improved endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
