DarkCloud Stealer is a Windows information-stealing malware family advertised in cybercrime forums since at least 2023 and observed in active campaigns from 2025 onward. It is designed to harvest sensitive data from compromised hosts, including browser credentials, mail client data, FTP client credentials, credit card information, screenshots, system and user information, and other stored account data. Stolen information is consolidated and exfiltrated to attacker-controlled infrastructure, and reporting also indicates use of mail-protocol-based operational channels in some campaigns.
Observed delivery has centered on phishing-driven infection chains. Campaigns have used email lures themed as purchase orders, fake software updates, and other social-engineering pretexts, including attachments such as archives containing JavaScript or Windows Script File downloaders, as well as PDF lures leading to archived payloads. Multiple campaigns used AutoIt-compiled droppers or obfuscated script stages that ultimately decrypted and launched the final stealer in memory. More recent variants added layered obfuscation through PowerShell and ConfuserEx-protected .NET loaders that unpack a final Visual Basic 6 payload.
DarkCloud Stealer employs substantial defense-evasion techniques. Documented samples use shellcode-assisted in-memory reconstruction, XOR- and 3DES-protected payload storage, RC4-encrypted strings, anti-tamper and control-flow obfuscation, and process hollowing to execute within a benign process. Samples also perform anti-analysis checks for debugging, monitoring, and virtualization tools. Persistence has been observed via Windows autorun mechanisms.
Targeting has included government organizations, technology entities, and financial institutions, with campaigns observed across multiple countries. DarkCloud Stealer has also been seen as a payload delivered by third-party malware-enablement services such as Cruciferra, indicating adoption by multiple cybercriminal operators rather than exclusive use by a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
A notable enhancement in this new variant is the incorporation of AutoIt compiled PE files as the dropper component.
At the beginning of the AutoIt script... function pointers are assigned to obscurely named global variables... The string-related global variables serve as the building blocks for a string decoding function used for additional obfuscation.
Upon closer examination, we see plainstones is an XOR-encrypted PE file... the shellcode... serves as the XOR decryption key for the previously mentioned plainstones file... Subsequently, the shellcode builds this PE file in memory and eventually executes it.
The payload attempts to retrieve saved usernames and passwords from various Chrome-based and Gecko-based browsers... the malware then checks each profile from the mail client and gathers saved credentials and data.
The payload attempts to retrieve saved usernames and passwords from various Chrome-based and Gecko-based browsers. | SMTP and FTP Credential Stealing This sample attempts to retrieve saved login credentials from various FTP client applications and decrypts them for exfiltration.
This sample also checks for the victim’s public IP address using the web services below to obtain geolocation. hxxp://showip[.]net hxxp://www[.]mediacollege[.]com/internet/utilities/show-ip.shtml
DarkCloud Stealer is a comprehensive data-stealing malware that collects and exfiltrates information such as: Computer names Usernames Screenshots Contacts
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer distributed via Cruciferra.
An infostealer observed being dropped by Cruciferra.
Credential-stealing malware distributed via email-based delivery chains that harvests stored login credentials from multiple FTP client applications, decrypts them, and stages them for exfiltration.
DarkCloud Stealer is an infostealer malware used in campaigns targeting financial institutions, designed to steal sensitive data from victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.