DarkCloud is a Windows information-stealing malware family first observed in 2022 and widely circulated as a low-cost commodity stealer sold through criminal marketplaces and Telegram. It is commonly implemented as a Visual Basic 6 infostealer and has appeared in multiple variants, including later rewritten releases such as version 4.2. DarkCloud is typically delivered through phishing campaigns using compressed attachments and financial, quotation, shipping, or business-themed lures, but it has also been observed in broader malware delivery chains involving JavaScript, PowerShell, .NET loaders, steganographic image payloads, malvertising, watering-hole activity, and compromised or infected websites and products. Some campaigns have used intermediate custom loaders such as PhantomVAI to deploy DarkCloud alongside other commodity malware families.
Once executed, DarkCloud steals a broad range of user and enterprise data from infected Windows systems. Confirmed collection targets include browser credentials, cookies, stored payment-card data, FTP credentials, email-client information, contact data, screenshots, keystrokes, clipboard contents, cryptocurrency wallet data, documents, and general system information. It has been observed accessing browser and application credential stores, querying SQLite-backed browser databases, and harvesting data from common browsers, FTP clients, and email applications.
DarkCloud commonly uses multi-stage execution chains and in-memory loading to hinder analysis and detection. Observed tradecraft includes obfuscated scripts, encrypted or embedded payload stages, .NET-based loaders, shellcode, process injection or hollowing into legitimate Windows processes, runtime string decryption, and checks for analysis or monitoring tools. Some variants delay activity until keyboard or mouse interaction is detected. Persistence mechanisms documented for DarkCloud include Startup-folder script placement, Run and RunOnce autoruns, and scheduled tasks.
Exfiltration is flexible and often redundant. DarkCloud has been observed transmitting stolen data over SMTP, FTP, HTTP POST, Telegram, and email-based channels, with some samples using multiple simultaneous exfiltration paths. The malware has targeted both individuals and organizations, with reporting specifically noting phishing activity against manufacturing-sector victims and broader campaigns aimed at enterprise users such as HR personnel. DarkCloud’s low cost, broad credential and data theft coverage, and compatibility with commodity loader ecosystems have made it a persistent component of the cybercrime infostealer landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples of Different Persistence Methods schtasks.exe /Create /TN "Updates\<RandName>" /XML "C:\Users\<user>\AppData\Local\Temp\<DroppedFile>"
Some of these can be scripts, covering a wide range of formats, from JAR and BAT to PowerShell (PS).
MITRE ATT&CK Mapping Tactic Technique ID Implementation Execution Command and Scripting: AutoIt T1059.010 AutoIt-compiled loader with WRSJLIM cipher
Examples of Different Persistence Methods schtasks.exe /Create /TN "Updates\<RandName>" /XML "C:\Users\<user>\AppData\Local\Temp\<DroppedFile>"
After multiple and varied obfuscation techniques for each type, the process leads either to a download or to the extraction of a binary.
Among these, there are many similar samples, often utilizing different obfuscators.
Threat actors in Q4 reused the same inexpensive, off the shelf components across multiple campaigns, combining obfuscated scripts, archive.org hosted images carrying embedded code, and a .NET loader to deliver different payloads.
[TA0005][T1036] Duplication of original files or loaders in temporary paths
Ultimately, everything culminates in the injection of a VB-based binary, which is the Stealer. This gets injected into a process of its choosing.
MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Indicator Removal: File Deletion T1070.004 Self-deletion via cmd /C @RD /S /Q
"DarkCloud... quietly harvests sensitive data, including browser logins, cookies, financial information, and contact details... focuses on extracting credentials and sensitive data from infected machines."
The final step is the theft of various types of information, including browser data, FTP credentials, screenshots, keylogging, and more.
“Multiple information stealer families… demand for off-the-key stealer malware… stealer logs… sold to initial access brokers”
Once injected, DarkCloud exhibits a wide range of malicious activities. It systematically gathers information from web browsers, collects system data, and even harvests credit card details.
[TA00011][T1071] Connection via noncommon process to TG bots ... https?:\/\/api\.telegram\.org\/bot\d+:[A-Za-z0-9_-]+\/
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer observed in phishing emails impersonating an electronics components manufacturer; it used compressed attachments containing executables and exfiltrated data over SMTP.
DarkCloud3
Infostealer distributed via email that collects documents, keystrokes, email client data, browser data, screenshots, and cryptocurrency wallet information.
Named as one of the malware families previously delivered by the PanthomVAI loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.