Security researchers have reported a significant resurgence and evolution of the DarkCloud infostealer malware, which is now being actively distributed in new campaigns targeting organizations. The latest version, DarkCloud 4.2, was identified during an attempted attack on a manufacturing sector client in September 2025. This version of the malware has been completely rewritten in Visual Basic 6 (VB6), a change that introduces new obfuscation techniques and makes detection more challenging for traditional security tools. The malware is now being sold on a dedicated website and distributed via Telegram, indicating a shift in its distribution channels following the temporary takedown of the XSS cybercrime forum, which previously served as its marketplace. Researchers from eSentire’s Threat Response Unit (TRU) observed that the primary infection vector remains phishing emails, with recent campaigns using financial-themed lures and malicious compressed attachments to trick recipients into executing the malware. Once installed, DarkCloud is capable of stealing a wide range of sensitive information, including credentials, cryptocurrency wallet data, and contact lists, making it a potent threat for both individuals and organizations. The malware’s new VB6-based obfuscation techniques further complicate analysis and remediation efforts, as highlighted by security analysts. In addition to credential theft, the latest DarkCloud variant is specifically engineered to target and exfiltrate cryptocurrency wallet information, reflecting the growing trend of financially motivated cybercrime. The malware’s operators have also improved its persistence mechanisms, allowing it to evade detection and maintain access to compromised systems for extended periods. Security experts warn that the combination of advanced obfuscation, expanded data theft capabilities, and aggressive distribution tactics significantly increases the risk posed by DarkCloud. The campaign’s reliance on phishing underscores the continued importance of user awareness and robust email security controls. Researchers emphasize that organizations should update their endpoint protection solutions and monitor for indicators of compromise associated with DarkCloud. The rapid evolution of the malware, including its migration to new sales platforms and technical enhancements, demonstrates the adaptability of cybercriminals in response to law enforcement actions. The incident serves as a reminder of the persistent threat posed by infostealer malware and the need for continuous vigilance in defending against evolving attack techniques. Security teams are advised to review their incident response plans and ensure that detection rules are updated to account for the latest DarkCloud behaviors. The resurgence of DarkCloud also highlights the interconnected nature of the cybercrime ecosystem, where disruptions to one platform can quickly lead to the emergence of new distribution channels. Organizations are encouraged to share threat intelligence and collaborate with industry peers to stay ahead of rapidly changing malware threats. The ongoing development and aggressive marketing of DarkCloud suggest that it will remain a significant threat in the near future, particularly for sectors handling sensitive financial and personal data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
eSentire TRU reported a sharp rise in DarkCloud activity, detailed the new variant's data-theft and exfiltration features, and released two tools to help researchers extract configuration data and deobfuscate the malware.
DarkCloud began being marketed through a dedicated website and Telegram channels, reflecting a relaunch and broader distribution model beyond forum sales.
In September 2025, eSentire TRU identified a rewritten DarkCloud Infostealer v4.2 during a blocked attack against a manufacturing-sector customer. The campaign used a phishing email themed as a SWIFT MT103 financial message with a malicious ZIP attachment.
Before its latest relaunch, DarkCloud was marketed to cybercriminals on the Russian-language forum XSS.is, indicating its earlier availability in underground markets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.