BlackSanta is a Windows malware component specialized in disabling endpoint security controls, functioning as an EDR-killer within a broader intrusion chain attributed to a Russian-speaking threat actor. It has been observed primarily in campaigns targeting human resources and recruitment personnel, where resume-themed lures are used to gain initial access. The infection chain commonly relies on spearphishing or recruitment-channel delivery of a malicious ISO image masquerading as a resume, followed by execution of a shortcut that launches obfuscated PowerShell, extracts steganographically concealed payloads, and uses DLL sideloading through a legitimate signed application. Subsequent stages perform host validation, anti-analysis checks, encrypted command-and-control, and in-memory execution of additional payloads.
BlackSanta’s defining capability is defense evasion through a Bring Your Own Vulnerable Driver technique. It loads legitimate but vulnerable signed kernel drivers to obtain low-level access, then enumerates and terminates antivirus, EDR, and related security processes at the kernel level. It has also been reported to weaken Microsoft Defender protections, add exclusions, suppress notifications, reduce telemetry and sample submission, and diminish system logging and security-console visibility. These actions are intended to clear the way for follow-on activity including credential harvesting, system reconnaissance, and data exfiltration with reduced resistance from host defenses.
The broader campaign associated with BlackSanta demonstrates disciplined intrusion tradecraft, combining social engineering, living-off-the-land execution, steganography, DLL sideloading, process hollowing, runtime decryption, and anti-VM or anti-debugging checks. Researchers have linked the operation to prolonged targeting of HR workflows, reflecting the high value of recruiter access and the tendency of HR staff to open unsolicited applicant materials under time pressure. BlackSanta is best characterized as a dedicated post-compromise security-disabling module used to facilitate stealthy information theft and further malicious operations on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The shortcut launches obfuscated PowerShell commands that extract hidden payloads embedded within a steganographic image.
“…when someone opens the file, it executes a malicious shortcut (LNK), triggering the next phase…”
“The shortcut launches obfuscated PowerShell commands…”
The shortcut launches obfuscated PowerShell commands that extract hidden payloads embedded within a steganographic image.
additional payloads delivered through process hollowing and fileless techniques to minimize forensic artifacts.
Suppresses system logging. Removes visibility from security consoles.
Aryaka's Aditya K Sood has uncovered BlackSanta, a new EDR killer that's being used in live malware campaigns.
It transmits detailed system-fingerprinting data to the attacker’s infrastructure and retrieves cryptographic material needed to decrypt embedded strings and instructions at runtime. Commands are dynamically decrypted and executed in memory
It inspects hostnames and username patterns, verifies system locale settings, and scans for virtualization artifacts commonly associated with sandboxes.
“the HypervisorEnforcedCodeIntegrity registry value is queried to determine whether Memory Integrity is enabled…”
The core function of BlackSanta is to terminate security processes, which it does by: enumerating running processes comparing the names against a large hardcoded list
It transmits detailed system-fingerprinting data to the attacker’s infrastructure
...terminate security processes... retrieving the matching process IDs using the loaded drivers to unlock and terminate those processes at the kernel level | It also modifies Windows Defender settings to weaken security... BlackSanta adds Microsoft Defender exclusions... and modifies a Registry value to reduce telemetry and automatic sample submission
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related-content navigation, not part of the main bind-link attack discussion.
A newly uncovered tool designed to disable or kill endpoint detection and response products during active malware campaigns.
A specialized module used to disable/evade endpoint detection and response (EDR) tooling as part of a staged infection chain delivered via phishing email. It enables full system compromise/control, performs host reconnaissance (OS, user accounts, configurations), and uses runtime decryption to hinder static detection and forensic analysis.
A BYOVD-based malware component used to disable antivirus, EDR, Microsoft Defender protections, and logging at the kernel level to facilitate stealth, credential theft, reconnaissance, and exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.