Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently Cyble Research Labs discovered a sample belonging to “Blackguard Stealer.” This stealer surfaced in the cybercrime forums in April 2021.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The stealer is written in C# and is obfuscated using Obfuscar tool... The TA has encoded a few strings using base64 and gzip compression
It is mostly distributed through malicious software disguised as Windows Update file, Fake MS Office Installer, Computer cleaner software, etc.
Now, it checks whether the execution is performed in the sandbox environment and whether the AntiVirus Product is installed. This is done by checking whether a specific library exists in the infected PC environment, and if a related library is detected, BlackGuard terminates itself.
After this, the malware checks for Discord tokens... extracts Discord tokens from them using regular expression.
MITRE ATT&CK® Techniques ... Credential Access ... T1539 Steal Web Session Cookie
If it finds a targeted VPN service, it steals the credentials from the configuration files, such as user.config
MITRE ATT&CK® Techniques ... Discovery T1007 System Service Discovery
Device information is stored in information.txt. It includes OS Version, CPU architecture, malware file location, screen size, current date and time, HWID, IPv4, country, and malware execution time.
MITRE ATT&CK® Techniques ... Discovery T1124 System Time Discovery
Now, it checks whether the execution is performed in the sandbox environment and whether the AntiVirus Product is installed. This is done by checking whether a specific library exists in the infected PC environment, and if a related library is detected, BlackGuard terminates itself.
The malware uses the Sleep() function several times as an anti-sandbox technique during its execution.
The malware first checks whether a VPN is installed or not by checking the directory “C:\Users\[username]\AppData\Local\[VPN name]”
After this, the malware identifies the user’s geolocation by sending a request to hxxps[:]//freegeoip[.]app/xml/.
BlackGuard browses Desktop, MyDocuments, and USERPROFILE\source path to steal specific files. It copies files with a file size of less than 2.5MB and has an extension such as *.txt, *.config, and *.rdp to the Files folder.
BlackGuard Stealer contains XOR-ed data inside a specific class used for stealing credentials and sensitive information, and each version has a different data or decoding method.
Send the zip file to the C2 server using HTTP/HTTPS protocol
The TA in this sample is using Telegram for exfiltrating the data... hxxps[:]//api.telegram.org/bot/sendDocument?chat_id=
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C# information stealer that collects browser data, local files, crypto wallet data, VPN credentials, Steam data, Discord tokens, FileZilla data, Telegram session data, system information, and screenshots, then compresses the stolen data into a ZIP archive and exfiltrates it via the Telegram Bot API.
A C# information stealer sold via a malware-as-a-service model. It uses obfuscation, anti-debugging, sleep-based anti-sandboxing, and timestomping, then steals browser credentials and data, crypto wallet data, VPN credentials, Steam data, Discord tokens, FileZilla data, Telegram session files, screenshots, system/geolocation information, and exfiltrates the collected data via Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.