Analysis of BlackGuard - Info Stealer Malware
ID: 02d0d1f5-97bd-5f78-9bce-04eb69328ca7
STIX ID: report--02d0d1f5-97bd-5f78-9bce-04eb69328ca7
Feed Name: Zscaler Security Research Blog
**BlackGuard stealer analysis** — Zscaler ThreatLabz describes BlackGuard, a .NET stealer sold as malware‑as‑a‑service that employs runtime string deobfuscation, anti‑debugging, anti‑CIS checks, and process termination to evade detection; it harvests browser credentials, crypto wallets, VPN and messenger data, packages stolen files into a ZIP and exfiltrates them to C2 servers, and the report includes technical details, IOCs (hashes and domains), and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
