216.73.216.6

DarkCloud Stealer: Comprehensive Analysis of a New Attack Chain That Employs AutoIt

· Published 14/05/2025 16:58 · Modified 21/05/2025 20:05

Export JSON

Essential information

Published
14/05/2025 16:58
Modified
21/05/2025 20:05
Tags
2025-05-14 anti-analysis autoit credential-theft darkcloud stealer information-stealing infostealer multi-stage payload obfuscation phishing
Related entities
1 vulnerabilities (cve), 4 observables, 12 techniques (mitre), 1 malware, 3 others

Description

Unit 42 researchers have identified a series of attacks distributing , an malware that has been active since 2022. The latest attack chain incorporates to evade detection and uses a file-sharing server to host the malware. The infection process begins with a email containing a RAR archive or a PDF that downloads the archive. The archive contains an -compiled executable that decrypts and executes the final payload. The malware steals sensitive data including browser passwords, credit card information, and email client credentials. It employs techniques and achieves persistence through registry modifications. The campaign has targeted various sectors, with a focus on government organizations, particularly in Poland.

External references