DarkCloud: An Advanced Stealer Malware Sold on Telegram to Target Windows Data
ID: de2600b3-89ed-5c99-9ad4-c87724bafe77
STIX ID: report--de2600b3-89ed-5c99-9ad4-c87724bafe77
Feed Name: GBHackers
DarkCloud is a Windows stealer first observed in 2022 and now widely marketed on Telegram; it spreads primarily via phishing (malicious invoices/fines) but also through malvertising, watering holes and bundling with other loaders. The malware uses multi-stage obfuscated loaders (PowerShell, JAR, VBS), performs in-memory injection to evade detection, implements persistence via startup items, registry and scheduled tasks, and harvests browser data, FTP/email credentials, payment card details, keylogs and screenshots while using Telegram bots for command-and-control and data exfiltration—organizations should prioritize phishing defenses, endpoint detection, and monitoring of startup/registry anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
