DarkCloud Infostealer Targets Enterprises With Scalable Credential Theft

In 2026, infostealers remain a significant threat, providing adversaries with an accessible and effective means of credential theft.

The DarkCloud Infostealer, first observed in 2022, is a prime example of how commercialized malware can disrupt enterprises.

Despite its low cost, DarkCloud proves to be an advanced threat capable of infiltrating corporate networks on targeting scalable credential theft across browsers, email clients, and other critical applications.

DarkCloud, developed by the infamous “Darkcloud Coder,” is marketed as surveillance software but is primarily used for credential harvesting.

Available for subscription at just $30, DarkCloud is sold through Telegram and a clearnet storefront, offering an easyentry point for cybercriminals.

While its official description highlights its keylogging functionality, DarkCloud’s true power lies in its broad infostealing capabilities.

It collects login credentials, financial data, and even contact lists, targeting applications like Outlook, FileZilla, NordVPN, and various popular browsers.

DarkCloud’s commercial model reflects a larger trend in the malware market, where developers package their tools into accessible, low-cost, and effective services.

This shift lowers the barrier for attackers and provides them with scalable methods to steal sensitive information at a fraction of the cost of custom-developed malware.

Why Visual Basic 6.0 Matters

DarkCloud’s use of Visual Basic 6.0 (VB6), an outdated programming language, is one of the most interesting aspects of its design.

A screenshot from DarkCloud’s clearnet site calling itself “surveillance software.” (Source: DarkCloud)
A screenshot from DarkCloud’s clearnet site calling itself “surveillance software.” (Source: DarkCloud)

While VB6 is no longer officially supported by Microsoft, it remains effective for malware developers due to its compatibility with legacy systems and reduced detection rates.

When analysts compared VB6 payloads to equivalent C/C++ code, the VB6 versions triggered fewer antivirus detections, showcasing how older programming languages can still be strategically advantageous.

This decision to use VB6, along with legacy components like MSVBVM60.DLL, allows DarkCloud to evade modern detection models while maintaining full functionality for credential theft.

This technique highlights that, even as malware evolves, older methods can still provide significant operational benefits to attackers.

Credential Theft At Scale

DarkCloud’s primary focus is on credential theft, targeting a wide array of applications and browsers to collect sensitive user data. The malware targets popular browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox, as well as email clients like Outlook and eM Client.

Additionally, it can steal credit card information, cookies, and login credentials, and even scrape contact lists from email applications, which can be used for future phishing campaigns.

Once the data is harvested, DarkCloud stores it locally in directories under the %APPDATA%\Microsoft\Windows\Templates path, enabling continuous exfiltration of sensitive information while maintaining structured log output for later transmission.

DarkCloud describes itself as a keylogger despite the original advertisement on XSS describing it as an infostealer. (Source: DarkCloud)
DarkCloud describes itself as a keylogger despite the original advertisement on XSS describing it as an infostealer. (Source: DarkCloud)

DarkCloud offers multiple exfiltration methods, including SMTP, FTP, Telegram, and HTTP. This flexibility enables attackers to adapt their exfiltration strategy based on their infrastructure preferences or operational security needs.

The malware uses hardcoded credentials for SMTP and FTP. Telegram sends data via bots, while HTTP is used less frequently.

The diverse exfiltration options further enhance DarkCloud’s capability, making it a highly adaptable and scalable tool for cybercriminals looking to harvest vast quantities of credentials and sensitive data.

Defending Against Commodity Infostealers

According to Flashpoint, DarkCloud and similar commodity infostealers may seem simple, but they can have devastating impacts on enterprises. To defend against such threats, organizations must implement proactive security measures.

This includes monitoring for unusual data exfiltration patterns, auditing for credential reuse across applications, and ensuring that incident response plans are in place for suspected compromises.

Targeted AppsExamples
BrowsersChrome, Edge, Firefox, Brave, Opera, Yandex, Vivaldi (steals logins, cookies, cards)
Email ClientsOutlook, eM Client, FoxMail, Thunderbird, 163Mail, MailMaster (plus contacts)
File TransferFileZilla, WinSCP, CoreFTP
OtherPidgin, NordVPN

As infostealers like DarkCloud continue to evolve, organizations must remain vigilant and incorporate real-time threat intelligence to enhance detection capabilities and prevent large-scale credential theft.

Follow us on Google NewsLinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories