logo

Analysis of BlackGuard - Info Stealer Malware

ID: 02d0d1f5-97bd-5f78-9bce-04eb69328ca7

STIX ID: report--02d0d1f5-97bd-5f78-9bce-04eb69328ca7

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**BlackGuard stealer analysis** — Zscaler ThreatLabz describes BlackGuard, a .NET stealer sold as malware‑as‑a‑service that employs runtime string deobfuscation, anti‑debugging, anti‑CIS checks, and process termination to evade detection; it harvests browser credentials, crypto wallets, VPN and messenger data, packages stolen files into a ZIP and exfiltrates them to C2 servers, and the report includes technical details, IOCs (hashes and domains), and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.