logo

Decoding the Inner Workings of DarkCloud Stealer

ID: 6e6fea19-16a6-5644-b3ee-9e69246c9f43

STIX ID: report--6e6fea19-16a6-5644-b3ee-9e69246c9f43

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2023-02-20

Date Updated: 2026-07-20

...
...

DarkCloud is an actively observed information-stealer distributed via spam campaigns and sold via a customizable builder; the report details a multi-stage infection chain (loader -> VB -> .NET payload), persistence via scheduled tasks, extensive credential and file harvesting from browsers, FTP clients, VPNs, crypto apps and password stores, and multiple exfiltration channels (SMTP, Telegram, web panel, FTP). The analysis provides sample hashes, code/resource extraction behavior, observed IoCs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.