Skip to content

DarkCloud

DarkCloud is a Windows information-stealing malware family first observed in 2022 and commonly sold as a low-cost commodity stealer through criminal marketplaces and Telegram.

Profile source: Mallory opens in a new tab

DarkCloud

Family profile

DarkCloud is a Windows information-stealing malware family first observed in 2022 and commonly sold as a low-cost commodity stealer through criminal marketplaces and Telegram. It is typically implemented in Visual Basic 6 and has appeared in multiple versions, including a rewritten v4.2 variant. DarkCloud is primarily used to harvest credentials and other sensitive data from infected systems, targeting web browsers, email clients, FTP clients, communication tools, and cryptocurrency-wallet-related data.

DarkCloud’s collection scope includes saved browser usernames and passwords, cookies, credit card and other browser-stored financial data, email client information and contacts, FTP credentials, screenshots, keystrokes, clipboard contents, documents, and system information. Reported targets include Chromium-based browsers, Firefox-based browsers, Outlook, Thunderbird, FoxMail, FileZilla, CoreFTP, WinSCP, and other locally stored application data sources. Some variants use bundled SQLite-related components to access browser credential databases and may query browser data stores directly to extract login and payment information.

The malware is most often delivered through phishing and spam campaigns using compressed attachments and lures themed as invoices, quotes, payment statements, shipment notices, or financial correspondence. Observed infection chains also include JavaScript, PowerShell, JAR, BAT, VBS, AutoIt, and .NET-based loaders, as well as multi-stage delivery using steganography or embedded payloads. DarkCloud has also been reported in campaigns involving malvertising, watering-hole activity, infected websites, and cracked-software-style lures, though phishing remains the most consistently documented vector. It is frequently delivered by intermediary loaders and crypter-like chains, and has been observed alongside other malware families such as ClipBanker, Agent Tesla, AsyncRAT, Remcos, XWorm, SmokeLoader, and payloads delivered by PhantomVAI/PanthomVAI-style loaders.

Execution and persistence behavior varies by campaign and version. Documented techniques include copying itself into user-accessible directories, establishing autorun through Run or RunOnce mechanisms, creating Startup-folder scripts, and scheduled-task persistence. Several campaigns used process hollowing or process injection into legitimate Windows processes such as MSBuild or svchost to execute the final stealer while reducing visibility. Anti-analysis and defense-evasion features include heavy string obfuscation or encryption, staged decryption, runtime loading, checks for analysis tools, and in some cases delaying activity until keyboard or mouse interaction is detected.

Exfiltration is flexible and commonly uses multiple simultaneous channels. Reported methods include SMTP email, Telegram bot communications, FTP upload, HTTP POST, and PHP-based web panels. This multi-channel design improves resilience when one exfiltration path is blocked. DarkCloud has been used in campaigns targeting both individuals and enterprises, with manufacturing among the specifically reported victim sectors. As a commodity infostealer with broad credential and data theft capability, DarkCloud can support follow-on intrusion activity including account compromise, fraud, phishing, and broader post-compromise operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 2, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • ReliableSite.Net LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

DarkCloud in ATT&CK

37 distinct techniques

Reporting

Research mentioning DarkCloud

Jul 15
Malware News

June 2026 Infostealer Trend Report - Malware Analysis - Malware Analysis, News and Indicators

ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Ahnlab Asec

June 2026 Infostealer Trend Report - ASEC

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.