BluStealer is a Windows credential-stealing malware family written primarily in Visual Basic with embedded C# .NET components. It is best characterized as an infostealer with additional keylogging, document theft, and cryptocurrency-focused theft functions. The malware has also been referred to as a310logger, although that name corresponds to only one namespace within its .NET component rather than the broader family.
BluStealer is primarily distributed through malspam and phishing campaigns using business-themed lures such as invoices, quotations, orders, and similar transactional messages. Observed campaigns have used impersonation themes including shipping and commercial correspondence, and have delivered payloads through downloadable archives or attached disk-image files containing executables packed with a distinctive .NET loader.
Its Visual Basic core reuses code from the SpyEx project and orchestrates execution of embedded .NET payloads recovered from resources and decrypted at runtime. The .NET credential-theft component reuses code from several open-source theft utilities, including ThunderFox, ChromeRecovery, StormKitty, and firepwd. Stolen data is written locally and then collected by the core component, which monitors output files and exfiltrates them when updated.
Documented capabilities include theft of browser and application credentials, keylogging, collection and upload of document files, and cryptocurrency theft through clipboard replacement for multiple wallet formats. BluStealer exfiltrates stolen information through SMTP and Telegram Bot API channels. Not every sample exposes every feature, but the family consistently centers on credential and information theft.
BluStealer also incorporates anti-analysis and defense-evasion measures. Samples use multiple string and payload protection methods, including XOR, RC4, and WinZip AES-based encryption, and perform virtualization checks through WMI properties and virtualization-related drivers. Execution may terminate when virtualized environments are detected. Related delivery chains have used a shared obfuscated .NET loader also seen with other commodity malware families; that loader can establish persistence and execute final payloads from embedded resources.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
BluStealer is primarily spread through malspam campaigns. ... Both samples contain .iso attachments and download URLs that the messages claim is a form that the lure claims the recipient needs to open and fill out to resolve a problem.
Each string is encrypted with a unique key. Depending on the sample, the encryption algorithm can be the xor cipher, RC4, or the WinZip AES implementation... The first stage of the .NET loader has a generic obfuscated look... The second stage has the function calls and strings obfuscated.
Then it executes one of the following command-line utilities to launch the .NET executable(s): ... AppLaunch.exe ... InstallUtil.e
Then it executes one of the following command-line utilities to launch the .NET executable(s): ... InstallUtil.e
Overview BluStealer is is a crypto stealer, keylogger, and document uploader...
Overview BluStealer is is a crypto stealer, keylogger, and document uploader...
The stolen credentials are written to “credentials.txt” ... The VB core will look for this drop and exfiltrate it later on.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET Stubs: Sowing the Seeds of Discord (PureCrypter) Aberebot AbstractEmu AdoBot 404 Keylogger Agent Tesla Amadey AsyncRAT Ave Maria BitRAT BluStealer Formbook LimeRAT Loki Password Stealer (PWS) Nanocore RAT Orcus RAT Quasar RAT Raccoon RedLine Stealer WhisperGate
BluStealer is a password stealer malware family, distributed via malspam, designed to steal credentials and sensitive data from victims.
Password-stealing malware observed distributed via an Italian malspam campaign themed around "Quotations" during the week of 08–14 September 2025.
Stealer mentioned due to overlap in observed downloader/network activity with this case.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.