BLISTER is an actively developed Windows malware loader first identified in 2021 and associated with financially motivated intrusions. It embeds encrypted malicious code and second-stage payloads within tampered legitimate DLLs or applications, at times using valid code-signing certificates to reduce detection. BLISTER decrypts and decompresses embedded payloads in memory and supports direct shellcode execution, reflective in-process PE loading, manual DLL mapping, and remote process hollowing or injection. Observed follow-on payloads include Cobalt Strike, BitRAT, Raccoon Stealer, MYTHIC implants, clipbankers, information stealers, remote-access trojans, and ransomware.
BLISTER employs extensive defense evasion, including API hashing, control-flow obfuscation, junk code, delayed execution and anti-debugging checks, native API use, selective domain-based environmental keying, and user-mode instrumentation unhooking. It commonly abuses Rundll32 for signed-binary proxy execution and can masquerade malicious activity within legitimate Windows processes. Persistence has been established by copying a malicious DLL and renamed Rundll32 binary to a local directory and creating a Startup-folder shortcut that invokes a DLL export at user logon.
BLISTER has been distributed through SOCGHOLISH/FakeUpdates infection chains, including fake browser-update lures delivered from compromised websites and drive-by downloads, as well as through malicious installers. It has been linked to campaigns that deploy Cobalt Strike and subsequently prepare systems for LockBit ransomware deployment. Public reporting also associates BLISTER activity with SOCGHOLISH, Amadey, and other financially motivated malware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“BLISTER, which is a malware loader associated with financially-motivated intrusions, relied on the rundll32.exe proxy built into every version of Microsoft Windows to launch their backdoor this year.”
Blister is a piece of malware that loads a payload embedded inside it. We provide an overview of payloads dropped by the Blister loader based on 137 unpacked samples from the past one and a half years and take a look at recent activity of Blister.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
A new process is created with the above command line to spawn a Rundll32 process via CreateProcessW Win32 API.
“Once decrypted, the embedded payload is loaded into the current process or injected into a newly spawned WerFault.exe process.”
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Observed adversary tactics and techniques lists "Process Injection: Process Hollowing"; the article also depicts "MYTHIC running inside injected WerFault process."
A new process is created with the above command line to spawn a Rundll32 process via CreateProcessW Win32 API.
“Finally, BLISTER establishes persistence by copying itself to the C:\ProgramData folder, along with a re-named local copy of rundll32.exe. A link is created in the current user’s Startup folder to launch the malware at logon.”
"The significant amount of benign code and use of encryption to protect the malicious code are likely two factors impacting detection."
It returns a pointer to the beginning of the packed PE... During the unpacking process of the payload, the malware starts by allocating memory... [and] stores a copy of encrypted/compressed payload in a buffer.
The BLISTER sample contains a function that gets Windows API addresses by hash; the practical example identifies calls to that resolver and renames assigned local variables using the API name recovered from an enum hash parameter.
BLISTER leverages the Rabbit stream cipher... with the 16-byte deciphering key and 8-byte IV. After the decryption stage, the payload is then decompressed using RtlDecompressBuffer with the LZNT1 compression format.
“BLISTER establishes persistence by copying itself to the C:\ProgramData folder, along with a re-named local copy of rundll32.exe.” The report also identifies “Windows Error Manager/Reporting Masquerading” and injection into “a newly spawned WerFault.exe process.”
“Once decrypted, the embedded payload is loaded into the current process or injected into a newly spawned WerFault.exe process.”
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Observed adversary tactics and techniques lists "Process Injection: Process Hollowing"; the article also depicts "MYTHIC running inside injected WerFault process."
The malware uses this file to read and write malicious DLL to this file. Werfault.exe is started by BLISTER and then the contents of this temporary DLL are loaded into memory into the Werfault process and the file is shortly deleted after.
“After the delay, it decrypts the embedded malware payload.”
“System Binary Proxy Execution ... representing almost half of those events. These utilities are present on all operating systems and facilitate code execution.”
“One such dropper writes a signed BLISTER loader to %temp%\Framwork\axsssig.dll and executes it with rundll32.”
"the malware proceeds to extract the machine's domain name using the GetComputerNameExW Windows API... [and] compares [its] hash to a hash present in the configuration."
401 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a loader using section mapping and SEC_IMAGE for payload loading.
Blister is referenced as a loader/backdoor observed as a downstream payload associated with SocGholish activity in 2024-2025.
With the release of v0.16, here are the different malware families that we cover. blister deprecated ghostpulse latrodectus lobshot lumma netwire redlinestealer remcos smokeloader stealc strelastealer xorddos
Referenced only as a malware family supported by the nightMARE analysis library; no behavior is described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.