BlackGuard is a .NET-based Windows infostealer operated as malware-as-a-service and promoted on Russian-language underground forums beginning in 2021, with broader public reporting emerging in early 2022. It is designed to harvest a wide range of sensitive data from infected systems, including browser-stored credentials, cookies, browsing history, autofill data, messaging application data, email and FTP credentials, VPN-related information, screenshots, and cryptocurrency wallet data. BlackGuard also targets browser-based wallet extensions and application data from numerous desktop wallets, enabling theft of both account access and cryptocurrency assets.
After execution, BlackGuard performs anti-analysis and evasion checks that have included process termination aimed at antivirus or sandbox tooling, runtime string obfuscation and decoding, anti-debugging behavior, and geofencing logic that causes the malware to exit on systems located in CIS countries. Reported variants have also used techniques such as API hooking, DLL injection, and resource hijacking to facilitate collection from browsers and client applications.
BlackGuard gathers data from Chromium- and Gecko-based browsers, messenger clients such as Telegram and Discord, email clients including Outlook, FTP tools, VPN clients, and cryptocurrency wallet software. It stages stolen information locally, often compressing it into ZIP or RAR archives, then exfiltrates the archive together with host profiling data over HTTP-based command-and-control channels. Earlier development stages reportedly used Telegram Bot API for exfiltration before later versions shifted to dedicated web-based command-and-control infrastructure and operator panels.
The malware has been observed distributed through phishing emails with malicious attachments, drive-by download activity, and lures such as game cheats or cracked software. BlackGuard has also appeared as a secondary payload in broader crimeware ecosystems. Its stolen data supports follow-on abuse including credential stuffing, account takeover, session hijacking through stolen cookies, online fraud, further malware deployment, and cryptocurrency theft. BlackGuard is notable for rapid iterative development, broad application coverage, and its role in the post-Raccoon resurgence of commodity infostealer activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The stealer contains a hardcoded array of bytes which is decoded in runtime to ASCII strings followed by base64 decoding. This allows it to bypass antivirus and string-based detection.
exit itself if the country is one among the Commonwealth of Independent States (CIS).
Once executed, it checks and kills the processes related to antivirus and sandbox as shown in the figure below.
Post Infection BlackGuard is focusing on valuable information such as cryptocurrency wallets, and browsers information including cookies, sessions, and history.
Once executed, it checks and kills the processes related to antivirus and sandbox as shown in the figure below.
The collected information is bundled in a ZIP file... and sent to the C2 server via a POST request, along with a system profiling report that sets a unique hardware ID for the victim and determines their location.
Once executed, it checks and kills the processes related to antivirus and sandbox as shown in the figure below.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET information stealer sold as malware-as-a-service that steals browser credentials, crypto wallets and wallet extensions, VPN and FTP credentials, email client data, and messenger data. It uses anti-detection, string obfuscation, anti-CIS checks, anti-debugging, and exfiltrates stolen data to a C2 server in a ZIP archive.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
A password-stealing malware mentioned only in a cited reference link.
Referenced as another infostealer distributed via social/video platforms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.