DarkCloud Stealer: Comprehensive Analysis of a New Attack Chain That Employs AutoIt
ID: f9b954cd-67db-5dc8-b36d-508f5dc2b1c8
STIX ID: report--f9b954cd-67db-5dc8-b36d-508f5dc2b1c8
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-05-14
Date Updated: 2026-04-28
Author: Pranay Kumar Chhaparwal and Benjamin Chang
Unit 42 identified a new AutoIt-based variant of DarkCloud Stealer (Jan–Feb 2025) that is distributed via phishing PDFs or RAR attachments hosted on public file-sharing services. The multi-stage chain uses an AutoIt-compiled dropper containing two encrypted data blobs (shellcode + XORed payload); the shellcode builds and executes the final DarkCloud PE in memory. The payload harvests browser, mail, FTP/SMTP credentials, screenshots and other sensitive data, employs anti-analysis checks and achieves persistence via RunOnce; the report includes sample hashes, the hosting URL and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
