Cyber Security News

DarkCloud – An Advanced Stealer Malware Selling Via Telegram To Steal Data From Windows

DarkCloud is a sophisticated stealer malware that emerged in 2022, quickly positioning itself as one of the most prevalent threats in its category.

This Windows-targeting malware has evolved significantly to extract sensitive information including browser data, FTP credentials, screenshots, keystrokes, and financial information from infected systems.

The primary distribution method involves phishing campaigns, where attackers impersonate legitimate companies or disguise their attacks as payment receipts or fines.

These attacks frequently target HR departments. Additional vectors include malvertising, watering hole attacks, and deployment alongside other malware such as DbatLoader or ClipBanker.

Security researcher REXorVc0 identified DarkCloud’s extensive capabilities, noting that the malware employs a multi-stage infection process designed to evade detection.

DarkCloud (Source – RexorVc0)

“The execution and distribution of this Stealer have been driven by phishing campaigns, where attackers impersonated various companies,” REXorVc0 explained in their technical analysis.

The impact has been significant, with numerous organizations falling victim to its data theft capabilities, losing browser data, cryptocurrency wallets, and credentials to attackers operating through Telegram channels.

Infection Mechanism

DarkCloud’s infection chain begins when a victim accesses a malicious link or downloads an infected file.

Attack Chain (Source – RexorVc0)

The initial payload, typically delivered as compressed files or scripts, kicks off a multi-stage process designed to bypass security controls.

The loader downloads or extracts the next stage, often employing sophisticated obfuscation techniques. One analyzed sample utilized Base64 encoding with TripleDES encryption:-

rgbKey = bytes([0x39, 0x1C, 0x8A, 0x9E, 0x80, 0xC2, 0xF8, 0xDF])
rgbIV = bytes([0xA3, 0x4B, 0x1F, 0xEB, 0x28, 0xFE, 0x46, 0xEA])

The final stage involves injecting the stealer into legitimate Windows processes like svchost.exe or MSBuild.

This technique allows DarkCloud to operate stealthily, evading most security solutions while harvesting sensitive data from browsers, password managers, and email clients to be exfiltrated through Telegram bots.

Are You from SOC/DFIR Team? - Try Free Malware Research with ANY.RUN - Start Now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago