Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
BluStealer is a Windows credential-stealing malware family written primarily in Visual Basic with embedded C# .NET components.
Profile source: Mallory opens in a new tabBluStealer
BluStealer is a Windows credential-stealing malware family written primarily in Visual Basic with embedded C# .NET components. It is best characterized as an infostealer with additional keylogging, document theft, and cryptocurrency-focused theft functions. The malware has also been referred to as a310logger, although that name corresponds to only one namespace within its .NET component rather than the broader family.
BluStealer is primarily distributed through malspam and phishing campaigns using business-themed lures such as invoices, quotations, orders, and similar transactional messages. Observed campaigns have used impersonation themes including shipping and commercial correspondence, and have delivered payloads through downloadable archives or attached disk-image files containing executables packed with a distinctive .NET loader.
Its Visual Basic core reuses code from the SpyEx project and orchestrates execution of embedded .NET payloads recovered from resources and decrypted at runtime. The .NET credential-theft component reuses code from several open-source theft utilities, including ThunderFox, ChromeRecovery, StormKitty, and firepwd. Stolen data is written locally and then collected by the core component, which monitors output files and exfiltrates them when updated.
Documented capabilities include theft of browser and application credentials, keylogging, collection and upload of document files, and cryptocurrency theft through clipboard replacement for multiple wallet formats. BluStealer exfiltrates stolen information through SMTP and Telegram Bot API channels. Not every sample exposes every feature, but the family consistently centers on credential and information theft.
BluStealer also incorporates anti-analysis and defense-evasion measures. Samples use multiple string and payload protection methods, including XOR, RC4, and WinZip AES-based encryption, and perform virtualization checks through WMI properties and virtualization-related drivers. Execution may terminate when virtualized environments are detected. Related delivery chains have used a shared obfuscated .NET loader also seen with other commodity malware families; that loader can establish persistence and execute final payloads from embedded resources.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.