TL;DR

Sample: ANY.RUN
Retro-C2 is a modern modular remote access trojan (RAT) and infostealer for Windows. The main goals are stealthily gaining full remote access to the victim's system and stealing confidential data. Retro-C2 has a web-oriented architecture: a lightweight encrypted Windows payload interacts with a control panel (C2), implemented as a modern web application in Go. This allows the operator to get real-time monitoring and a convenient interface for managing infected hosts. It uses advanced evasion techniques: reflective loading of modules directly into memory and direct system calls (Direct Syscalls) to bypass EDR/AV hooks. This allows the malware to execute its main payload without writing to disk and to hide traces from traditional antivirus solutions and sandboxes. Retro-C2 is capable of extracting sensitive data from browser memory such as cookies, saved passwords, and payment information, bypassing standard access mechanisms. In addition to stealer features, it provides a full set of RAT capabilities: remote command execution (CMD/PowerShell), screen capture, keylogger, clipboard interception, audio recording from the microphone, file/process/registry management, etc.
How to detect: Detection of Retro-C2 is based on specific string artifacts embedded in the malicious client's binary file. The key detection method is a YARA rule targeting a combination of unique logging strings that reflect the structure of the Retro-C2 logic and its individual modules.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Submission | Sandbox Evasion |
|---|---|---|---|
| 2025-12-23 | News | 2026-01-14 | 2 |
Yara
rule Retro_C2_RAT {
meta:
description = "Detects Retro-C2 RAT - C++ based trojan with reflective DLL loading, direct syscalls (Tartarus Gate), ChaCha20 encryption, credential theft, keylogging, and wallet scanning capabilities"
date = "2025-12-23"
reference = "https://threatmon.io/retro-c2-a-new-breed-of-open-source-remote-access-trojan/"
author = "ANY.RUN"
threat = "retro-c2"
tags = "retro-c2, rat"
strings:
$x1 = "\\Retro C2\\" ascii
$x2 = "GoAheadClient.pdb" fullword ascii
$x3 = "C:\\Windows\\Temp\\retro_exec\\" fullword ascii
$x4 = "[RETRO CLIENT]" fullword ascii
$s1 = "Starting connection to " fullword ascii
$s2 = "Connected successfully!" fullword ascii
$s3 = "Connection failed, retrying in 5 seconds..." fullword ascii
$s4 = "[ERROR] Failed to create socket: " fullword ascii
$s5 = "[ERROR] Invalid address: " fullword ascii
$s6 = "[ERROR] Connection failed: " fullword ascii
$s7 = "[WALLET SCANNER] Scanning: " fullword ascii
$s8 = "[WALLET SCANNER] Unknown error scanning " fullword ascii
$s9 = "[WALLET SCANNER] Scan complete. Found " fullword ascii
$s10 = "[WALLET SCANNER] handleScanWallets exception: " fullword ascii
$s11 = "[WALLET SCANNER] Filesystem error: " fullword ascii
$s12 = "[SCREENSHOT] Encoded to base64: " fullword ascii
$s13 = "[ERROR] Failed to send message: " fullword ascii
$s14 = "[FILE UPLOAD] Starting upload of " fullword ascii
$s15 = "[CLIENT] Starting execution: " fullword ascii
$s16 = "[EXECUTE] Executing file: " fullword ascii
$s17 = "[FILE MANAGER] Starting upload: " fullword ascii
condition:
uint16(0) == 0x5A4D and
(
(all of ($x*) and 4 of ($s*)) or
(any of ($x*) and 10 of ($s*))
)
}
IOCs:
635afd6a09d123b3d9c62791fe7435154a6c326ccf8beebc0a06cce10eafb00fad57fd24e49498bced9ac874d998f2a595.85.7.11:7382MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1620 | Reflective Code Loading | Retro-C2 loads the encrypted DLL directly into memory using ReflectiveLoader (in-memory execution without writing to disk). |
| T1562.001 | Impair Defenses: Disable or Modify Tools | Uses Direct Syscalls: the malware calls system functions directly, bypassing API hooks of EDR/AV for stealthy operations. |
| T1027 | Obfuscated Files or Information | ChaCha20 encryption of payload: main modules are stored/transmitted encrypted and decrypted only at runtime. |
| T1071.001 | Application Layer Protocol: Web Protocols | Communication via HTTP(S) with JSON — fully web-oriented C2 infrastructure masking traffic as legitimate web traffic. |
| T1555.003 | Credentials from Web Browsers | Extracts saved passwords, cookies, and payment data from browser memory. |
| T1056.001 | Input Capture: Keylogging | Built-in keylogger silently records keystrokes to steal passwords and sensitive input. |
| T1115 | Clipboard Data | Monitors clipboard to steal copied data (passwords, wallets, text, etc.). |
| T1123 | Audio Capture | Can activate microphone and record audio for eavesdropping. |
| T1113 | Screen Capture | Remote desktop viewing: captures screenshots/screen video and sends to operator in real time. |
| T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Operator can execute arbitrary cmd.exe commands via web panel. |
| T1059.001 | Command and Scripting Interpreter: PowerShell | Remote PowerShell execution for scripts and one-liners. |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys | Adds itself to Run keys or Startup folder for persistence. |
| T1053.005 | Scheduled Task/Job: Scheduled Task | Creates hidden scheduled task for periodic or logon-based execution. |
| T1543.003 | Create or Modify System Process: Windows Service | Installs itself as Windows service for persistent execution on boot. |

Sample: ANY.RUN
Scarface is an infostealer collecting various types of data: credentials, browser data (cookies, history, autofill), credit card information, and cryptocurrency wallets. Targets victims across a wide range of countries.
How to detect: Detection is carried out by monitoring obfuscated command lines, in particular heavily encoded PowerShell commands. When decoding Base64 Get-CimInstance Win32_PortConnector | Measure-Object | Select-Object -ExpandProperty Count
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-01-14 | Post | 2026-01-14 | 0 |
Using the following TI Lookup query, you can search for recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:" -EncodedCommand RwBlAHQALQBDAGkAbQBJAG4AcwB0AGEAbgBjAGUA"
IOCs:
399aa72837df2c8d36d0f1f502ed5cc11da27ffdb4ef29291ec998e82484442e8c37d02d6f1f0585e5d6c8c045e7b4cf420dac05fa6982a36dd28ce3763ab31c29c42e6cb043b5619ca65b64861acb2a522cae5052e03bad1a7e9a2c50b7631c8f63d7074bc736508451a100afeb2b77077c0ac505e6bdb2607a8aec9787dab730290b74335c2296f9d55082e328e3859e56f65eb77e888804fe6932f1bde0aeMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.001 | Command and Scripting Interpreter: PowerShell | Starts powershell.exe for command execution |
| T1027.010 | Obfuscated Files or Information: Command Obfuscation | Uses heavily obfuscated/encoded command lines |
| T1012 | Query Registry | Reads multiple registry keys |
| T1057 | Process Discovery | Enumerates running processes |
| T1082 | System Information Discovery | Collects system information |

Sample: ANY.RUN
Santastealer is a new infostealer under the Malware-as-a-Service model, actively promoted via Telegram and underground forums. According to OSINT data, the malware recently underwent rebranding from BluelineStealer and in December 2025 was officially announced by the developers as ready for use in real attacks.
How to detect: Detection is carried out using a YARA rule focused on the unique string "SantaStealer" and characteristic logging/path strings.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Submission | Sandbox Evasion |
|---|---|---|---|
| 2025-12-17 | News | 2025-12-22 | 7 |
Yara
rule santastealer {
meta:
description = "Detects SantaStealer information-stealing malware targeting credentials, browser data, Discord tokens, Steam tokens, and system information"
date = "2025-12-17"
author = "ANY.RUN"
threat = "santastealer"
tags = "santastealer, stealer"
strings:
$x1 = "SantaStealer" fullword ascii
$s1 = "Important Files\\Steam\\Steam Tokens.txt" fullword ascii
$s2 = "Important Files\\Discord\\Tokens.txt" fullword ascii
$s3 = "Extensions\\Extensions.txt" fullword ascii
$s4 = "AppData|Local|BraveSoftware|Brave-Browser|User Data" fullword ascii
$s5 = "BrowserSummary.txt" fullword ascii
$s6 = "[HISTORY] Starting history collection" fullword ascii
$s7 = "[HISTORY] Adding combined file: %s (size: %zu)" fullword ascii
$s8 = "[MEMORY] Total files collected: %d" fullword ascii
$s9 = "[MEMORY] No files to write to Log.zip" fullword ascii
$s10 = "VM Detection: Suspicious computer name detected" fullword ascii
$s11 = "VM Detection: Blacklisted process detected" fullword ascii
$s12 = "VM Detection: Timing anomaly detected" fullword ascii
$s13 = "- NetBIOS: %s" fullword ascii
$s14 = "- Language: %s" fullword ascii
$s15 = "- CPU Vendor: %s" fullword ascii
$s16 = "%s\\Clipboard.txt" fullword ascii
condition:
uint16(0) == 0x5A4D and $x1 and 7 of ($s*)
}
IOCs:
26c3abc8bf32ff0f548adfa3c5fdf430c9bf061865512b83c4559553e668766cC:\Users\admin\Desktop\Log.zipstealer.suMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059 | Command and Scripting Interpreter | Payload and modules executed from exported DLL functions (e.g., payload_main). |
| T1555.003 | Credentials from Web Browsers | Extracts browser passwords, cookies, autofill, and history. |
| T1552.004 | Credentials: Private Keys | Steals crypto wallet data and other stored private keys. |
| T1082 | System Information Discovery | Enumerates environment to collect target information for exfiltration. |
| T1497 | Virtualization/Sandbox Evasion | Anti-VM checks and execution delay to evade sandbox detection. |
| T1041 | Exfiltration Over C2 Channel | Splits collected ZIP archives and uploads over HTTP to hardcoded endpoints. |
| T1560.002 | Archive via Library | Uses in-memory ZIP creation for data compression before exfiltration. |
1) Open-source RATs are becoming more accessible: Retro-C2’s open access and ready-made builder lower the entry barrier even for beginner attackers.
2) Diversification of delivery and execution techniques: Stealer-class threats demonstrate not only functional diversity but also flexibility in execution methods. The combination of multi-stage loaders, scripting interpreters, and modular architecture allows them to more effectively bypass protective mechanisms.
3) The MaaS model contributes to the evolution of threats: The rebranding of BluelineStealer to Santastealer and its public promotion reflect market mechanisms within the underground ecosystem, where competition stimulates the development of functionality.