A recent cyberattack campaign leveraging the DarkCloud stealer has been identified, targeting Spanish companies and local offices of international organizations across various industries.
The attackers are spoofing a legitimate Spanish company specializing in mountain and skiing equipment to deliver malicious payloads via email.
The emails, which use billing-themed social engineering tactics, feature subjects such as Importe: 3.500,00 EUR and include a weaponized .TAR archive file named Importe3.50000EUR_Transfer.tar.
Within the archive lies a DarkCloud stealer binary designed to exfiltrate sensitive data.
The campaign has been observed targeting sectors such as technology, legal, finance, healthcare, energy, food, chemical, government, manufacturing, and packaging.
This marks an escalation in the activity of the DarkCloud stealer, which has been in use since at least 2022 but has seen increased deployment in recent months.
DarkCloud is a commodity stealer equipped with advanced features that make it a potent tool for cybercriminals.
Its capabilities include capturing keystrokes, clipboard content, and screenshots; recovering passwords from popular browsers such as Chrome, Opera, Yandex, and 360 Browser; extracting cookies and saved credentials; and stealing sensitive files from email clients and cryptocurrency applications.
The malware also hijacks wallet addresses for cryptocurrencies like Bitcoin (BTC), Ethereum (ETH), and Ripple (XRP).
In addition to these functionalities, DarkCloud exfiltrates documents in formats such as .txt, .xls, .xlsx, .pdf, and .rtf.
It employs multiple channels for data exfiltration, including SMTP email protocols, Telegram messaging services, and FTP servers.
To evade detection by security systems, the malware incorporates anti-virtual machine checks, anti-debugging measures, and fake API calls to disguise its behavior.
According to the Report, Broadcom’s Symantec division has implemented robust protection mechanisms to counter this threat.
Symantec’s security solutions identify DarkCloud-related malicious indicators through multiple layers of defense:
The increasing prevalence of attacks utilizing commodity stealers like DarkCloud underscores the importance of multi-layered security strategies for organizations across all industries.
By employing advanced detection techniques and leveraging machine learning models alongside traditional security measures, Symantec aims to mitigate risks posed by evolving cyber threats.
This campaign highlights the need for vigilance among businesses operating in targeted sectors to protect themselves against sophisticated phishing tactics and data theft attempts.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…
Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…
The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…