logo

New Infection Chain and ConfuserEx-Based Obfuscation for DarkCloud Stealer

ID: 334c7f69-cf4a-5f9b-a781-2c1262f1de6f

STIX ID: report--334c7f69-cf4a-5f9b-a781-2c1262f1de6f

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-08-07

Date Updated: 2026-04-28

Author: Pranay Kumar Chhaparwal, Benjamin Chang and Lee Wei Yeong

...
...

Unit 42 researchers describe an active DarkCloud Stealer campaign that delivers a ConfuserEx-protected .NET loader which decrypts and injects a VB6 infostealer via multi-stage phishing archives (RAR/TAR/7Z) and obfuscated JS/WSF/PowerShell downloaders; the report includes technical analysis of protections and deobfuscation steps, indicators of compromise (hashes, URLs, Telegram C2), and mitigation guidance for detection and prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.