BluStealer

July 7, 2022

BluStealer, first detected in May 2021 by Twitter user James_inthe_box, is an information-stealing malware with the ability to steal cyrpto wallet data, swap crypto addresses present in the clipboard, find and steal document files, exfiltrate data through SMTP and the Telegram Bot API and more.

Recently, it’s authors decided to step up its powers by giving it the ability to bypass EDRs and evade process-based defenses. This is in addition to its existing anti-forensic and anti-VM capabilities, making BluStealer a major threat to security teams.

Explore the BluStealer Spotlight now and get to know BluStealer’s attack flow and capabilities as well as the main techniques it employs such as process hollowing and direct syscalls.

Past campaigns

images

Sandworm

Spotlight on APT44 (Sandworm): Defend Against a Notorious Threat APT44—also known as Sandworm, ELECTRUM, and VOODOO BEAR—is a destructive threat group linked to Russia’s Unit […]

Read More
images

Fancy Bear

Inside This Campaign: Stay Ahead of Emerging ThreatsDiscover Fancy Bear (APT28)•Who they are: A Russian cyber-espionage group linked to military intelligence.•Their mission: Advanced geopolitical intelligence […]

Read More
images

OFBiz Vulnerability

Discover & Defend: Apache OFBiz SpotlightUncover the critical vulnerability lurking in Apache OFBiz, the open-source ERP system at the core of Atlassian JIRA, used by […]

Read More