Last seven days
- First activity
- Aug 4, 2026
- Last activity
- Aug 4, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram.
Profile source: Mallory opens in a new tabDarkCloud
DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram. It is commonly implemented as a Visual Basic 6 infostealer and has appeared in multiple variants, including later rewritten releases such as version 4.2. DarkCloud is typically delivered through phishing campaigns using compressed attachments and financial, quotation, shipping, or business-themed lures, but it has also been observed in broader malware delivery chains involving JavaScript, PowerShell, .NET loaders, steganographic image payloads, malvertising, watering-hole activity, and compromised or infected websites and products. Some campaigns have used intermediate custom loaders such as PhantomVAI to deploy DarkCloud alongside other commodity malware families.
Once executed, DarkCloud steals a broad range of user and enterprise data from infected Windows systems. Confirmed collection targets include browser credentials, cookies, stored payment-card data, FTP credentials, email-client information, contact data, screenshots, keystrokes, clipboard contents, cryptocurrency wallet data, documents, and general system information. It has been observed accessing browser and application credential stores, querying SQLite-backed browser databases, and harvesting data from common browsers, FTP clients, and email applications.
DarkCloud commonly uses multi-stage execution chains and in-memory loading to hinder analysis and detection. Observed tradecraft includes obfuscated scripts, encrypted or embedded payload stages, .NET-based loaders, shellcode, process injection or hollowing into legitimate Windows processes, runtime string decryption, and checks for analysis or monitoring tools. Some variants delay activity until keyboard or mouse interaction is detected. Persistence mechanisms documented for DarkCloud include Startup-folder script placement, Run and RunOnce autoruns, and scheduled tasks.
Exfiltration is flexible and often redundant. DarkCloud has been observed transmitting stolen data over SMTP, FTP, HTTP POST, Telegram, and email-based channels, with some samples using multiple simultaneous exfiltration paths. The malware has targeted both individuals and organizations, with reporting specifically noting phishing activity against manufacturing-sector victims and broader campaigns aimed at enterprise users such as HR personnel. DarkCloud’s low cost, broad credential and data theft coverage, and compatibility with commodity loader ecosystems have made it a persistent component of the cybercrime infostealer landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
0a71bbd1903835fcbcb323179b460238184a4b406a3f3eab7341b0b003a26b6a 313a75fac905707219d67f0814e7bc38b5acae5d82b7700c4afd5c5906ceccec 8e75624f82af4054dceda9ee302cab4e95a0038159839cdb619d490f01707b3e d0a8c7f680f9573add4c7d681fbfee2bfd8a4c3cf606e98e2b136a63ef85348d df4e3e6182bb1d5163fbcbfec6426936513d8f2cdb284d7791e09a379cc63edd MITRE ATT&CK
Reporting
ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.