Skip to content

BluStealer

BluStealer is a Windows credential-stealing malware family written primarily in Visual Basic with embedded C# .NET components.

Profile source: Mallory opens in a new tab

BluStealer

Family profile

BluStealer is a Windows credential-stealing malware family written primarily in Visual Basic with embedded C# .NET components. It is best characterized as an infostealer with additional keylogging, document theft, and cryptocurrency-focused theft functions. The malware has also been referred to as a310logger, although that name corresponds to only one namespace within its .NET component rather than the broader family.

BluStealer is primarily distributed through malspam and phishing campaigns using business-themed lures such as invoices, quotations, orders, and similar transactional messages. Observed campaigns have used impersonation themes including shipping and commercial correspondence, and have delivered payloads through downloadable archives or attached disk-image files containing executables packed with a distinctive .NET loader.

Its Visual Basic core reuses code from the SpyEx project and orchestrates execution of embedded .NET payloads recovered from resources and decrypted at runtime. The .NET credential-theft component reuses code from several open-source theft utilities, including ThunderFox, ChromeRecovery, StormKitty, and firepwd. Stolen data is written locally and then collected by the core component, which monitors output files and exfiltrates them when updated.

Documented capabilities include theft of browser and application credentials, keylogging, collection and upload of document files, and cryptocurrency theft through clipboard replacement for multiple wallet formats. BluStealer exfiltrates stolen information through SMTP and Telegram Bot API channels. Not every sample exposes every feature, but the family consistently centers on credential and information theft.

BluStealer also incorporates anti-analysis and defense-evasion measures. Samples use multiple string and payload protection methods, including XOR, RC4, and WinZip AES-based encryption, and perform virtualization checks through WMI properties and virtualization-related drivers. Execution may terminate when virtualized environments are detected. Related delivery chains have used a shared obfuscated .NET loader also seen with other commodity malware families; that loader can establish persistence and execute final payloads from embedded resources.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DE1

Leading providers

  • DigitalOcean, LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

BluStealer in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.