Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Spear-Phishing Attack Deploys DarkCloud Malware to Steal Keystrokes and Credentials

In September 2025, eSentire's Threat Response Unit (TRU) identified a spear-phishing campaign targeting a mid-sized manufacturer’s Zendesk support inbox. The attackers employed a banking-themed email lure titled "Swift Message MT103 Addiko Bank ad:…

In September 2025, eSentire's Threat Response Unit (TRU) identified a spear-phishing campaign targeting a mid-sized manufacturer’s Zendesk support inbox. The attackers employed a banking-themed email lure titled "Swift Message MT103 Addiko Bank ad: FT2521935SVT" and attached a malicious zip file named "Swift Message MT103 FT2521935SVT.zip". This file contained the DarkCloud version 3.2, a tool designed for information theft.

DarkCloud, initially distributed on the XSS.is forum, has been updated from .NET to VB6, incorporating features such as string encryption and sandbox evasion checks. Once executed, it harvests sensitive data, including browser passwords, credit card information, cookies, keystrokes, FTP credentials, email contacts, files, and cryptocurrency wallets. Exfiltration occurs through Telegram, FTP, SMTP, or PHP web panels.

The phishing email originated from procure@bmuxitq[.]shop, masquerading as legitimate financial communication. The attackers sought to deceive analysts into executing the malware under the guise of a transaction update.

DarkCloud's builder necessitates the use of the VB6 IDE for local compilation, exposing source code and enabling unauthorized modifications. The latest version, DarkCloud 4.2, supports optional string encryption using a VB6-specific Caesar cipher. Analysts can decrypt obfuscated strings by reverse-engineering the msvbvm60.dll’s rtcRandomize and rtcRandomNext implementations, revealing exfiltration credentials and command-and-control endpoints.

Additional capabilities include system profiling via WMI, VBScript-powered credit-card regex parsing, and email contact harvesting. The malware uses sandbox and VM detection techniques, such as process name checks and disk/memory thresholds, to evade analysis.

In September 2025, eSentire's Threat Response Unit (TRU) identified a spear-phishing campaign targeting a mid-sized manufacturer’s Zendesk support inbox.
Angela Waters · Thehackingpost

Persistence is achieved through randomized RunOnce registry entries. DarkCloud targets documents, spreadsheets, PDFs, and cryptocurrency wallets for data theft.

DarkCloud gathers the victim's external IP address using utilities like showip[.]net and mediacollege[.]com, then sends logs via various channels, including SMTP, Telegram API, FTP, or PHP web panels. PCAP analysis confirms these methods in real-world traffic captures.

eSentire's SOC analysts quickly identified and quarantined the malicious emails, blocking the DarkCloud executable. They assisted with remediation efforts, including credential resets and enhanced email security measures.

Advertisement

Implement email protection rules to block ZIP attachments containing executable files. Conduct Phishing and Security Awareness Training to educate staff on social engineering tactics. Partner with a 24/7 Managed Detection and Response (MDR) service for continuous threat monitoring and rapid response. Deploy Next-Gen Antivirus or Endpoint Detection and Response (EDR) solutions to detect and contain infostealers.

Organizations can mitigate the risk posed by threats like DarkCloud by combining proactive threat hunting, security awareness, and advanced analytics.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories