MISTCLOAK (Malware Family) By Fraunhofer FKIE Archived: 2026-04-05 17:56:30 UTC Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW. [TLP:WHITE] win_mistcloak_auto (20251219 | Detects win.mistcloak.) Source: https://malpedia.caad.fkie.fraunhofer.de/details/win.mistcloak https://malpedia.caad.fkie.fraunhofer.de/details/win.mistcloak Page 1 of 1