Skip to content

DarkCloud

DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram.

Profile source: Mallory opens in a new tab

DarkCloud

Family profile

DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram. It is commonly implemented as a Visual Basic 6 infostealer and has appeared in multiple variants, including later rewritten releases such as version 4.2. DarkCloud is typically delivered through phishing campaigns using compressed attachments and financial, quotation, shipping, or business-themed lures, but it has also been observed in broader malware delivery chains involving JavaScript, PowerShell, .NET loaders, steganographic image payloads, malvertising, watering-hole activity, and compromised or infected websites and products. Some campaigns have used intermediate custom loaders such as PhantomVAI to deploy DarkCloud alongside other commodity malware families.

Once executed, DarkCloud steals a broad range of user and enterprise data from infected Windows systems. Confirmed collection targets include browser credentials, cookies, stored payment-card data, FTP credentials, email-client information, contact data, screenshots, keystrokes, clipboard contents, cryptocurrency wallet data, documents, and general system information. It has been observed accessing browser and application credential stores, querying SQLite-backed browser databases, and harvesting data from common browsers, FTP clients, and email applications.

DarkCloud commonly uses multi-stage execution chains and in-memory loading to hinder analysis and detection. Observed tradecraft includes obfuscated scripts, encrypted or embedded payload stages, .NET-based loaders, shellcode, process injection or hollowing into legitimate Windows processes, runtime string decryption, and checks for analysis or monitoring tools. Some variants delay activity until keyboard or mouse interaction is detected. Persistence mechanisms documented for DarkCloud include Startup-folder script placement, Run and RunOnce autoruns, and scheduled tasks.

Exfiltration is flexible and often redundant. DarkCloud has been observed transmitting stolen data over SMTP, FTP, HTTP POST, Telegram, and email-based channels, with some samples using multiple simultaneous exfiltration paths. The malware has targeted both individuals and organizations, with reporting specifically noting phishing activity against manufacturing-sector victims and broader campaigns aimed at enterprise users such as HR personnel. DarkCloud’s low cost, broad credential and data theft coverage, and compatibility with commodity loader ecosystems have made it a persistent component of the cybercrime infostealer landscape.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 4, 2026
Last activity
Aug 4, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

DarkCloud in ATT&CK

36 distinct techniques

Reporting

Research mentioning DarkCloud

Jul 15
Malware News

June 2026 Infostealer Trend Report - Malware Analysis - Malware Analysis, News and Indicators

ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Ahnlab Asec

June 2026 Infostealer Trend Report - ASEC

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.