BlackGuard emerged as a .NET/C# malware-as-a-service infostealer sold on Russian-speaking underground forums for about $200 per month or $700 lifetime, gaining traction as other stealers faded from the market. Researchers said the malware was under active development and evolved through multiple versions, with early builds borrowing code from families such as 44Caliber, StormKitty, and Echelon. Across variants, BlackGuard targeted browser credentials and cookies, autofill data, cryptocurrency wallets and wallet extensions, VPN and FTP accounts, email clients, Discord and Telegram data, Steam, FileZilla, screenshots, geolocation, and files stored under the victim's profile directory.
The malware used layered evasion and anti-analysis techniques, including obfuscation, packed or encoded strings, antivirus and sandbox process termination, debugger checks, input blocking, repeated sleep delays, timestomping, and a CIS geofence that caused samples to exit on systems in Commonwealth of Independent States countries. Stolen data was typically staged locally, compressed into ZIP archives, and exfiltrated either through the Telegram Bot API in earlier variants or via HTTP POST to hard-coded command-and-control servers in later versions. Analysis of exposed BlackGuard infrastructure showed victim data from countries including the United States, United Kingdom, Sweden, and Switzerland, underscoring the malware's role in credential theft, session hijacking, account takeover, fraud, and cryptocurrency theft.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
S2W reported that BlackGuard activity increased in March 2022 based on the proportion of discovered samples. This indicates a measurable rise in the malware's operational presence.
A major BlackGuard update added support for stealing wallet extensions from Chrome, Edge, and Edge Beta. This reflects a functional expansion of the stealer's cryptocurrency theft capabilities.
BlackGuard activity resumed in earnest in January 2022 after the operator sent a deposit and tested the product. Sources also describe January 2022 as the period when the seller advertised BlackGuard on Russian-language forums and it first appeared publicly there.
An additional BlackGuard promotional post was uploaded and then temporarily suspended because the operator had not sent a sale deposit. The suspension reflects early sales friction around the malware's underground marketing.
BlackGuard surfaced on cybercrime forums in April 2021, indicating the malware had entered underground circulation by that month. Multiple sources describe this as an early appearance before its broader 2022 activity.
The first promotional post for BlackGuard was uploaded on the XSS dark web forum under the title "New Stealer." This marks the earliest explicit forum promotion of the malware in the provided sources.
Researchers identified an exposed BlackGuard command-and-control administrator panel and analyzed stolen archives stored on it. The data showed victims in countries including Sweden, Switzerland, the UK, and the US, and illustrated how stolen credentials, cookies, wallet data, and messaging artifacts were organized for follow-on abuse.
S2W TALON published a historical analysis of BlackGuard covering its evolution from early code reuse through versions v1.x, v2, v2.4, and v3.5. The report described shifts from Telegram Bot API exfiltration to hard-coded HTTP/HTTPS C2 URLs and changes in anti-analysis and data encoding.
S2W published an analysis describing BlackGuard as a C# infostealer active through at least Q1 2022, linking it to 44Caliber Stealer and documenting its Telegram-based exfiltration, anti-debugging, and distribution methods. The report also tied the malware to seller identities on XSS and BHF forums.
Cyble Research Labs analyzed a BlackGuard Stealer sample and multiple variants observed in the wild, documenting its C# implementation, anti-analysis behavior, credential theft targets, and Telegram Bot API exfiltration. The report also noted customizable clipper functionality and improving evasion across newer variants.
Researchers reported BlackGuard as a new .NET infostealer sold on Russian underground forums under a malware-as-a-service model for $200 monthly or $700 lifetime. The reporting also highlighted its active development, anti-analysis features, CIS geofencing, and HTTP POST exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 88 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcef5.com
Open sourcemedium.com
Open sourcecyberint.com
Open sourcemedium.com
Open sourcethehackernews.com
Open sourceblog.cyble.com
Open sourcezdnet.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.