BlackSanta is a Russian-speaking threat actor associated with a multi-stage spearphishing campaign active since at least October 2025. The actor has targeted human resources personnel with resume-themed lures to obtain initial access, using disk image delivery to help bypass Windows trust protections. The intrusion chain includes hidden script execution, steganographic payload extraction, DLL sideloading through a legitimate application, and extensive anti-analysis checks before payload deployment. A notable characteristic of BlackSanta’s tradecraft is aggressive defense evasion. The actor has used a Bring Your Own Vulnerable Driver technique involving Adlice TrueSight to terminate a large set of endpoint detection and antivirus products from kernel mode. After suppressing defenses, the malware enables elevated privileges, performs process hollowing into a Windows system process, tampers with local security settings, installs a rogue root certificate to facilitate HTTPS interception, and establishes persistence through a scheduled task. The malware also removes components and unloads the driver after use to reduce forensic visibility. Operationally, BlackSanta has demonstrated post-compromise control through an ASP.NET-based command-and-control framework and has shown signs of Russian-language ecosystem familiarity, including infrastructure characteristics consistent with a Russian-speaking operator. Available evidence supports characterization as a Russian-speaking cybercriminal or intrusion actor, but does not establish Russian state sponsorship. No additional confirmed aliases or sub-groups are currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.