DarkCloud Stealer is a Windows information-stealing malware family advertised in cybercrime forums since at least 2023 and observed in active campaigns from 2025 onward. It is designed to harvest sensitive data from compromised hosts, including browser-stored credentials, cookies and other browser data, email client credentials, FTP client credentials, screenshots, system and user information, and payment-card data. Reported targeting has included government organizations, financial institutions, and technology-sector victims, with campaigns observed across multiple countries.
DarkCloud Stealer has been distributed primarily through phishing-driven delivery chains. Observed lures have included purchase-order themed documents and fake software-update prompts. Multiple infection chains have been documented, including AutoIt-based droppers and archive-delivered JavaScript or Windows Script File downloaders that retrieve PowerShell stages. More recent variants have used layered obfuscation, including ConfuserEx-protected .NET loaders that decrypt a final Visual Basic 6 payload and execute it via process hollowing into a legitimate Windows process. Other samples have used shellcode and in-memory reconstruction of the final payload from encrypted embedded components.
The malware emphasizes anti-analysis and evasion. Documented variants perform checks for debugging, monitoring, and virtualization tools, use encrypted or obfuscated strings, and rely on staged decryption routines to hinder static and dynamic analysis. Persistence has been observed through Windows autorun mechanisms, including RunOnce. DarkCloud Stealer has also been seen delivered by third-party malware-enablement services such as Cruciferra and deployed alongside other commodity malware by operators of families such as XWorm.
Core functionality centers on credential theft and data collection for exfiltration. DarkCloud targets Chromium-based and Gecko-based browsers, mail clients, and FTP applications, and can decrypt stored credentials before sending them to attacker-controlled infrastructure. Some reporting also associates DarkCloud operations with use of mail-protocol-based channels and Telegram-backed command-and-control or exfiltration workflows. Overall, DarkCloud Stealer is best characterized as a commodity but actively evolving infostealer focused on broad credential and data theft from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
A notable enhancement in this new variant is the incorporation of AutoIt compiled PE files as the dropper component.
At the beginning of the AutoIt script... function pointers are assigned to obscurely named global variables... The string-related global variables serve as the building blocks for a string decoding function used for additional obfuscation.
Upon closer examination, we see plainstones is an XOR-encrypted PE file... the shellcode... serves as the XOR decryption key for the previously mentioned plainstones file... Subsequently, the shellcode builds this PE file in memory and eventually executes it.
The payload attempts to retrieve saved usernames and passwords from various Chrome-based and Gecko-based browsers... the malware then checks each profile from the mail client and gathers saved credentials and data.
The payload attempts to retrieve saved usernames and passwords from various Chrome-based and Gecko-based browsers. | SMTP and FTP Credential Stealing This sample attempts to retrieve saved login credentials from various FTP client applications and decrypts them for exfiltration.
This sample also checks for the victim’s public IP address using the web services below to obtain geolocation. hxxp://showip[.]net hxxp://www[.]mediacollege[.]com/internet/utilities/show-ip.shtml
DarkCloud Stealer is a comprehensive data-stealing malware that collects and exfiltrates information such as: Computer names Usernames Screenshots Contacts
T1071.003 Mail Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
If the key is not found, the client sends a 'sendplugin' command to the C2 server ... The C2 server then responds with the command 'savePlugin' along with a base64 encoded string containing the plugin | We observed XWorm RAT Operators execute additional malware, such as: DarkCloud Stealer ... Remcos RAT
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer distributed via Cruciferra.
An infostealer observed being dropped by Cruciferra.
Credential-stealing malware distributed via email-based delivery chains that harvests stored login credentials from multiple FTP client applications, decrypts them, and stages them for exfiltration.
Additional stealer malware deployed by XWorm operators on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.