HomeSecurityDarkCloud Stealer targets financial institutions

DarkCloud Stealer targets financial institutions

DarkCloud Stealer has recently emerged and is already becoming a powerful threat targeting financial institutions through convincing phishing campaigns. Attackers use infected RAR attachments that pretend to be valid documents and deliver a multi-stage JavaScript-based payload.

DarkCloud Stealer

Upon opening the file, victims execute a VBE script that uses Windows Script Host to launch a PowerShell downloader hidden in innocent-looking image files. This initial access method exploits users' trust in common financial correspondence, triggering an automated decoding and decryption chain designed to evade conventional security checks.

See also: New Yurei Ransomware encrypts files with ChaCha20

In early September 2025, security teams noticed a dramatic increase in malicious RAR attachments being sent to corporate email accounts in the banking sector . CyberProof analysts discovered that the file named “Proof of Payment.rar” contains a VBE script that, when executed, calls PowerShell to download an embedded JPG file named universe-1733359315202-8750.jpg . The stealer loader is hidden within this image, and the decryption routine extracts the .NET DLL module directly from the image’s pixel data.

CyberProof researchers noted that the PowerShell script meticulously checks memory offsets to detect a distinct BMP header pattern before building the loader DLL. Once the DLL is rebuilt in memory, the script calls [Reflection.Assembly]::Load() to execute the loader without ever touching disk.

DarkCloud Stealer: Persistence and credential theft

Once loaded into memory, the DarkCloud Stealer establishes persistence  by copying a JavaScript payload to the Windows Run registry key with a disguised filename (M3hd0pf.exe pretending to be MSBuild.exe), ensuring execution on every user login. The stealer then injects itself into legitimate processes such as MSBuild.exe and mtstocom.exe using process hollowing techniques . This allows it to extract stored credentials from databases browser such as Chrome's Login Data.

See also: WhiteCobra: Malicious extensions in the VSCode market

Endpoint detection platform alerts confirm DPAPI access events and memory mapping to browser, revealing attempts to decrypt stored passwords directly in memory. Finally, the stolen data is stored in user directories and exported via FTP and HTTP channels to dynamic domain clusters (.shop, .xyz), making detection at the network level difficult.

DarkCloud Stealer targets financial institutions

Modern attacks on the financial sector

The rise of DarkCloud Stealer confirms a key pattern of modern cyberattacks: targeted financial fraud that combines high-quality social engineering with memory-to-memory techniques and pushes traditional defenses to the sidelines. These attacks are carefully designed campaigns with quality deceptive messages and professional deliverables.

The business model behind DarkCloud has three characteristics that make it dangerous. First, attackers use complex, multi-stage loaders hidden within attachments (compressed or “virtual” files), reducing easy detection by basic email filters. Second, the payload is often “loaded” directly into memory — that is, it is not written cleanly to disk — so traditional signature- and file-scanning-based solutions do not easily catch it. Third, the extraction of data is done via a variety of protocols and dynamic domain clusters, which complicates analysis and blocking.

For financial services organizations, the response must be multi-layered. Technical measures — such as strict rules for VBS/VBE execution, Windows Script Host restriction, strict enforcement of PowerShell policies (Constrained Language Mode, logging, transcription), and enabling EDR with in-memory load detection — significantly reduce the successful scope of campaigns. In addition, networks should filter outbound connections to unrecognized TLDs and implement rules to prevent FTP/HTTP exfiltration.

DarkCloud Stealer targets financial institutions

But technicalities alone are not enough: the human side remains the weakest point. Training staff in realistic phishing scenarios, tabletop exercises for incident response , and clear incident reporting procedures reduce the likelihood of an open door. Implementing MFA for critical interfaces, managing keys/wallets off-endpoints, and isolating test/production environments are critical policies with immediate impact.

See also: BitlockMove tool allows lateral movement & COM Hijacking

At a strategic level, organizations should share technology and threat intelligence: common IOC flags, EDR rules, and up-to-date domain lists help stop attacks quickly. At the same time, security teams should invest in memory analysis and sandboxing that runs PowerShell/VBS scripts in isolated environments to uncover “living off the land” techniques used by attackers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS