BlackParty is a trojan identified by SCILabs in a Mexico-focused campaign that impersonates Mexico’s tax authority, Servicio de Administración Tributaria (SAT). The campaign uses a fake SAT-themed website at hxxps://elindio[.]com[.]mx/sat with visitor validation and geofencing logic to selectively present malicious content to intended victims while showing the legitimate SAT site to others. Victims are prompted to complete a CAPTCHA and download a supposed manual, delivered as Sat.zip containing Sat.bat. The batch file uses PowerShell to download, decompress, and execute additional payloads from hxxps://elindio[.]com[.]mx/sat/redir[.]php.
The malware generates a malicious file named bs_gu.d, checks OS architecture, abuses LaunchWinApp.exe to load malicious code, and establishes persistence in %AppData%\Local\Microsoft\Windows\Explorer and %AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup. SCILabs reported that BlackParty includes components written in Rust and a loader written in C++, uses in-memory execution techniques, and employs anti-sandbox, anti-debugging, and heavy obfuscation. It uses ChaCha20-encrypted communications with command-and-control infrastructure.
BlackParty is designed to add infected devices to a botnet and provide full remote control of compromised systems. It also performs information theft, including collection of a unique victim identifier, OS information, installed antivirus, OS architecture, and user permission context. Collected data is exfiltrated to fiestadrops[.]cc/chanclas/upload[.]php. SCILabs also reported theft related to business services including Office365, Outlook, and OneDrive. Samples were observed in the wild for several months with low detection rates on VirusTotal. Additional reported indicators include the SAT-themed delivery infrastructure, Sat.zip, Sat.bat, bs_gu.d, abuse of LaunchWinApp.exe, and a downloaded executable signed by "HB Sistemas 2012 C.A" with certificate email totalsoftware.lzarate[@]gmail.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family referenced as part of campaigns leveraging overlapping/shared infrastructure domains in the region.
Trojan used in a Mexico-focused campaign that impersonates the Mexican tax authority (SAT) to trick users into downloading a ZIP/BAT dropper chain. Establishes persistence, collects host/security metadata, communicates with a C2 using ChaCha20-encrypted channels, supports remote control, and steals information including business-service credentials/data (e.g., Office365/Outlook/OneDrive). Uses LaunchWinApp.exe to load malicious code and includes anti-sandbox/anti-debugging and heavy obfuscation; components written in Rust and C++.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.