Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
DarkCloud is a Windows information-stealing malware family first observed in 2022 and commonly sold as a low-cost commodity stealer through criminal marketplaces and Telegram.
Profile source: Mallory opens in a new tabDarkCloud
DarkCloud is a Windows information-stealing malware family first observed in 2022 and commonly sold as a low-cost commodity stealer through criminal marketplaces and Telegram. It is typically implemented in Visual Basic 6 and has appeared in multiple versions, including a rewritten v4.2 variant. DarkCloud is primarily used to harvest credentials and other sensitive data from infected systems, targeting web browsers, email clients, FTP clients, communication tools, and cryptocurrency-wallet-related data.
DarkCloud’s collection scope includes saved browser usernames and passwords, cookies, credit card and other browser-stored financial data, email client information and contacts, FTP credentials, screenshots, keystrokes, clipboard contents, documents, and system information. Reported targets include Chromium-based browsers, Firefox-based browsers, Outlook, Thunderbird, FoxMail, FileZilla, CoreFTP, WinSCP, and other locally stored application data sources. Some variants use bundled SQLite-related components to access browser credential databases and may query browser data stores directly to extract login and payment information.
The malware is most often delivered through phishing and spam campaigns using compressed attachments and lures themed as invoices, quotes, payment statements, shipment notices, or financial correspondence. Observed infection chains also include JavaScript, PowerShell, JAR, BAT, VBS, AutoIt, and .NET-based loaders, as well as multi-stage delivery using steganography or embedded payloads. DarkCloud has also been reported in campaigns involving malvertising, watering-hole activity, infected websites, and cracked-software-style lures, though phishing remains the most consistently documented vector. It is frequently delivered by intermediary loaders and crypter-like chains, and has been observed alongside other malware families such as ClipBanker, Agent Tesla, AsyncRAT, Remcos, XWorm, SmokeLoader, and payloads delivered by PhantomVAI/PanthomVAI-style loaders.
Execution and persistence behavior varies by campaign and version. Documented techniques include copying itself into user-accessible directories, establishing autorun through Run or RunOnce mechanisms, creating Startup-folder scripts, and scheduled-task persistence. Several campaigns used process hollowing or process injection into legitimate Windows processes such as MSBuild or svchost to execute the final stealer while reducing visibility. Anti-analysis and defense-evasion features include heavy string obfuscation or encryption, staged decryption, runtime loading, checks for analysis tools, and in some cases delaying activity until keyboard or mouse interaction is detected.
Exfiltration is flexible and commonly uses multiple simultaneous channels. Reported methods include SMTP email, Telegram bot communications, FTP upload, HTTP POST, and PHP-based web panels. This multi-channel design improves resilience when one exfiltration path is blocked. DarkCloud has been used in campaigns targeting both individuals and enterprises, with manufacturing among the specifically reported victim sectors. As a commodity infostealer with broad credential and data theft capability, DarkCloud can support follow-on intrusion activity including account compromise, fraud, phishing, and broader post-compromise operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Reporting
ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.