logo

DarkCloud: An Advanced Stealer Malware Sold on Telegram to Target Windows Data

ID: de2600b3-89ed-5c99-9ad4-c87724bafe77

STIX ID: report--de2600b3-89ed-5c99-9ad4-c87724bafe77

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-03-31

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

DarkCloud is a Windows stealer first observed in 2022 and now widely marketed on Telegram; it spreads primarily via phishing (malicious invoices/fines) but also through malvertising, watering holes and bundling with other loaders. The malware uses multi-stage obfuscated loaders (PowerShell, JAR, VBS), performs in-memory injection to evade detection, implements persistence via startup items, registry and scheduled tasks, and harvests browser data, FTP/email credentials, payment card details, keylogs and screenshots while using Telegram bots for command-and-control and data exfiltration—organizations should prioritize phishing defenses, endpoint detection, and monitoring of startup/registry anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.