DarkCloud Stealer: Comprehensive Analysis of a New Attack Chain That Employs AutoIt
Essential information
- Published
- 14/05/2025 16:58
- Modified
- 21/05/2025 20:05
- Tags
- 2025-05-14 anti-analysis autoit credential-theft darkcloud stealer information-stealing infostealer multi-stage payload obfuscation phishing
- Related entities
- 1 vulnerabilities (cve), 4 observables, 12 techniques (mitre), 1 malware, 3 others
Description
Unit 42 researchers have identified a series of attacks distributing DarkCloud Stealer, an information-stealing malware that has been active since 2022. The latest attack chain incorporates AutoIt to evade detection and uses a file-sharing server to host the malware. The infection process begins with a phishing email containing a RAR archive or a PDF that downloads the archive. The archive contains an AutoIt-compiled executable that decrypts and executes the final DarkCloud Stealer payload. The malware steals sensitive data including browser passwords, credit card information, and email client credentials. It employs anti-analysis techniques and achieves persistence through registry modifications. The campaign has targeted various sectors, with a focus on government organizations, particularly in Poland.