Last seven days
- First activity
- Jul 21, 2026
- Last activity
- Jul 21, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram.
Profile source: Mallory opens in a new tabDarkCloud
DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram. It is commonly implemented as a Visual Basic 6 infostealer and has appeared in multiple variants, including later rewritten releases such as version 4.2. DarkCloud is typically delivered through phishing campaigns using compressed attachments and financial, quotation, shipping, or business-themed lures, but it has also been observed in broader malware delivery chains involving JavaScript, PowerShell, .NET loaders, steganographic image payloads, malvertising, watering-hole activity, and compromised or infected websites and products. Some campaigns have used intermediate custom loaders such as PhantomVAI to deploy DarkCloud alongside other commodity malware families.
Once executed, DarkCloud steals a broad range of user and enterprise data from infected Windows systems. Confirmed collection targets include browser credentials, cookies, stored payment-card data, FTP credentials, email-client information, contact data, screenshots, keystrokes, clipboard contents, cryptocurrency wallet data, documents, and general system information. It has been observed accessing browser and application credential stores, querying SQLite-backed browser databases, and harvesting data from common browsers, FTP clients, and email applications.
DarkCloud commonly uses multi-stage execution chains and in-memory loading to hinder analysis and detection. Observed tradecraft includes obfuscated scripts, encrypted or embedded payload stages, .NET-based loaders, shellcode, process injection or hollowing into legitimate Windows processes, runtime string decryption, and checks for analysis or monitoring tools. Some variants delay activity until keyboard or mouse interaction is detected. Persistence mechanisms documented for DarkCloud include Startup-folder script placement, Run and RunOnce autoruns, and scheduled tasks.
Exfiltration is flexible and often redundant. DarkCloud has been observed transmitting stolen data over SMTP, FTP, HTTP POST, Telegram, and email-based channels, with some samples using multiple simultaneous exfiltration paths. The malware has targeted both individuals and organizations, with reporting specifically noting phishing activity against manufacturing-sector victims and broader campaigns aimed at enterprise users such as HR personnel. DarkCloud’s low cost, broad credential and data theft coverage, and compatibility with commodity loader ecosystems have made it a persistent component of the cybercrime infostealer landscape.
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.