TL;DR

  • Retro-C2 (Windows RAT): A modern open-source remote access trojan in C++ with reflective DLL loading, direct syscalls (Tartarus Gate), ChaCha20 encryption, credential theft, keylogging, and cryptocurrency wallet scanning. Available via Telegram/GitHub, it includes a convenient web panel in Go. Detection is possible via YARA using unique strings.
  • Scarface (Windows stealer): An infostealer collecting credentials, browser data, credit cards, and cryptocurrency wallets. Targets a wide range of countries, often uses multiple loaders. Detection is possible via obfuscated PowerShell commands.
  • Santastealer (Windows stealer): A new MaaS infostealer (rebranding of BluelineStealer), modular, operates in memory, collects browser data, messengers, Steam, documents, and wallets. Detection is possible via YARA.

1) Retro-C2 (Windows)

Sample: ANY.RUN

Retro-C2 is a modern modular remote access trojan (RAT) and infostealer for Windows. The main goals are stealthily gaining full remote access to the victim's system and stealing confidential data. Retro-C2 has a web-oriented architecture: a lightweight encrypted Windows payload interacts with a control panel (C2), implemented as a modern web application in Go. This allows the operator to get real-time monitoring and a convenient interface for managing infected hosts. It uses advanced evasion techniques: reflective loading of modules directly into memory and direct system calls (Direct Syscalls) to bypass EDR/AV hooks. This allows the malware to execute its main payload without writing to disk and to hide traces from traditional antivirus solutions and sandboxes. Retro-C2 is capable of extracting sensitive data from browser memory such as cookies, saved passwords, and payment information, bypassing standard access mechanisms. In addition to stealer features, it provides a full set of RAT capabilities: remote command execution (CMD/PowerShell), screen capture, keylogger, clipboard interception, audio recording from the microphone, file/process/registry management, etc.

How to detect: Detection of Retro-C2 is based on specific string artifacts embedded in the malicious client's binary file. The key detection method is a YARA rule targeting a combination of unique logging strings that reflect the structure of the Retro-C2 logic and its individual modules.

Key facts:

  • Use of reflective DLL loading and direct syscalls (Tartarus Gate) for code execution in memory without disk involvement and bypassing protective hooks.
  • The main module is encrypted with the ChaCha20 algorithm and decrypted only upon C2 command.
  • Management via a web interface with JSON exchange over HTTP(S).
  • Functionality includes interception of credentials from browser memory, keylogging, remote command execution, screenshots, audio recording, and scanning of cryptocurrency wallets.
  • Distributed in open access via Telegram and GitHub with a ready-made build constructor.

Analytical note:

Detected External sources ANY.RUN Submission Sandbox Evasion
2025-12-23 News 2026-01-14 2

Yara

rule Retro_C2_RAT {
        meta:
            description = "Detects Retro-C2 RAT - C++ based trojan with reflective DLL loading, direct syscalls (Tartarus Gate), ChaCha20 encryption, credential theft, keylogging, and wallet scanning capabilities"
            date = "2025-12-23"
            reference = "https://threatmon.io/retro-c2-a-new-breed-of-open-source-remote-access-trojan/"
            author = "ANY.RUN"
            threat = "retro-c2"
            tags = "retro-c2, rat"

            
        strings:
            $x1 = "\\Retro C2\\" ascii
            $x2 = "GoAheadClient.pdb" fullword ascii
            $x3 = "C:\\Windows\\Temp\\retro_exec\\" fullword ascii
            $x4 = "[RETRO CLIENT]" fullword ascii
            
            $s1 = "Starting connection to " fullword ascii
            $s2 = "Connected successfully!" fullword ascii
            $s3 = "Connection failed, retrying in 5 seconds..." fullword ascii
            $s4 = "[ERROR] Failed to create socket: " fullword ascii
            $s5 = "[ERROR] Invalid address: " fullword ascii
            $s6 = "[ERROR] Connection failed: " fullword ascii
            $s7 = "[WALLET SCANNER] Scanning: " fullword ascii
            $s8 = "[WALLET SCANNER] Unknown error scanning " fullword ascii
            $s9 = "[WALLET SCANNER] Scan complete. Found " fullword ascii
            $s10 = "[WALLET SCANNER] handleScanWallets exception: " fullword ascii
            $s11 = "[WALLET SCANNER] Filesystem error: " fullword ascii
            $s12 = "[SCREENSHOT] Encoded to base64: " fullword ascii
            $s13 = "[ERROR] Failed to send message: " fullword ascii
            $s14 = "[FILE UPLOAD] Starting upload of " fullword ascii
            $s15 = "[CLIENT] Starting execution: " fullword ascii
            $s16 = "[EXECUTE] Executing file: " fullword ascii
            $s17 = "[FILE MANAGER] Starting upload: " fullword ascii
            
        condition:
            uint16(0) == 0x5A4D and 
            (
                (all of ($x*) and 4 of ($s*)) or
                (any of ($x*) and 10 of ($s*))
            )
    }

IOCs:

  • SHA256: 635afd6a09d123b3d9c62791fe7435154a6c326ccf8beebc0a06cce10eafb00f
  • MD5 (output_75168779.exe): ad57fd24e49498bced9ac874d998f2a5
  • C2: 95.85.7.11:7382

MITRE:

Technique ID Technique Name Evidence
T1620 Reflective Code Loading Retro-C2 loads the encrypted DLL directly into memory using ReflectiveLoader (in-memory execution without writing to disk).
T1562.001 Impair Defenses: Disable or Modify Tools Uses Direct Syscalls: the malware calls system functions directly, bypassing API hooks of EDR/AV for stealthy operations.
T1027 Obfuscated Files or Information ChaCha20 encryption of payload: main modules are stored/transmitted encrypted and decrypted only at runtime.
T1071.001 Application Layer Protocol: Web Protocols Communication via HTTP(S) with JSON — fully web-oriented C2 infrastructure masking traffic as legitimate web traffic.
T1555.003 Credentials from Web Browsers Extracts saved passwords, cookies, and payment data from browser memory.
T1056.001 Input Capture: Keylogging Built-in keylogger silently records keystrokes to steal passwords and sensitive input.
T1115 Clipboard Data Monitors clipboard to steal copied data (passwords, wallets, text, etc.).
T1123 Audio Capture Can activate microphone and record audio for eavesdropping.
T1113 Screen Capture Remote desktop viewing: captures screenshots/screen video and sends to operator in real time.
T1059.003 Command and Scripting Interpreter: Windows Command Shell Operator can execute arbitrary cmd.exe commands via web panel.
T1059.001 Command and Scripting Interpreter: PowerShell Remote PowerShell execution for scripts and one-liners.
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys Adds itself to Run keys or Startup folder for persistence.
T1053.005 Scheduled Task/Job: Scheduled Task Creates hidden scheduled task for periodic or logon-based execution.
T1543.003 Create or Modify System Process: Windows Service Installs itself as Windows service for persistent execution on boot.

2) Scarface (Windows)

Sample: ANY.RUN

Scarface is an infostealer collecting various types of data: credentials, browser data (cookies, history, autofill), credit card information, and cryptocurrency wallets. Targets victims across a wide range of countries.

How to detect: Detection is carried out by monitoring obfuscated command lines, in particular heavily encoded PowerShell commands. When decoding Base64 Get-CimInstance Win32_PortConnector | Measure-Object | Select-Object -ExpandProperty Count

Key facts:

  • Scarface often uses multiple loaders and downloadable components for delivery and execution.

Analytical note:

Detected External sources ANY.RUN Submission Sandbox Evasion
2026-01-14 Post 2026-01-14 0

Using the following TI Lookup query, you can search for recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:" -EncodedCommand RwBlAHQALQBDAGkAbQBJAG4AcwB0AGEAbgBjAGUA"

IOCs:

  • SHA256: 399aa72837df2c8d36d0f1f502ed5cc11da27ffdb4ef29291ec998e82484442e
  • SHA256: 8c37d02d6f1f0585e5d6c8c045e7b4cf420dac05fa6982a36dd28ce3763ab31c
  • SHA256: 29c42e6cb043b5619ca65b64861acb2a522cae5052e03bad1a7e9a2c50b7631c
  • SHA256: 8f63d7074bc736508451a100afeb2b77077c0ac505e6bdb2607a8aec9787dab7
  • SHA256: 30290b74335c2296f9d55082e328e3859e56f65eb77e888804fe6932f1bde0ae

MITRE:

Technique ID Technique Name Evidence
T1059.001 Command and Scripting Interpreter: PowerShell Starts powershell.exe for command execution
T1027.010 Obfuscated Files or Information: Command Obfuscation Uses heavily obfuscated/encoded command lines
T1012 Query Registry Reads multiple registry keys
T1057 Process Discovery Enumerates running processes
T1082 System Information Discovery Collects system information

3) Santastealer (Windows)

Sample: ANY.RUN

Santastealer is a new infostealer under the Malware-as-a-Service model, actively promoted via Telegram and underground forums. According to OSINT data, the malware recently underwent rebranding from BluelineStealer and in December 2025 was officially announced by the developers as ready for use in real attacks.

How to detect: Detection is carried out using a YARA rule focused on the unique string "SantaStealer" and characteristic logging/path strings.

Key facts:

  • Collects credentials, documents, cryptocurrency wallets, browser and messenger data (Telegram, Discord, Steam).
  • Fully modular multithreaded architecture with 14 different modules.
  • Operates primarily in memory (fileless execution) to avoid detection.
  • Built-in Chrome decryptor bypassing AppBound Encryption.
  • Basic anti-analysis checks (VM, debugger, processes).
  • Supports reflective code loading, process hollowing, and dynamic API resolution.

Analytical note:

Detected External sources ANY.RUN Submission Sandbox Evasion
2025-12-17 News 2025-12-22 7

Yara

rule santastealer {
        meta:
            description = "Detects SantaStealer information-stealing malware targeting credentials, browser data, Discord tokens, Steam tokens, and system information"
            date = "2025-12-17"
            author = "ANY.RUN"
            threat = "santastealer"
            tags = "santastealer, stealer"


         
        strings:
            $x1 = "SantaStealer" fullword ascii

            $s1 = "Important Files\\Steam\\Steam Tokens.txt" fullword ascii
            $s2 = "Important Files\\Discord\\Tokens.txt" fullword ascii
            $s3 = "Extensions\\Extensions.txt" fullword ascii
            $s4 = "AppData|Local|BraveSoftware|Brave-Browser|User Data" fullword ascii
            $s5 = "BrowserSummary.txt" fullword ascii
            $s6 = "[HISTORY] Starting history collection" fullword ascii
            $s7 = "[HISTORY] Adding combined file: %s (size: %zu)" fullword ascii
            $s8 = "[MEMORY] Total files collected: %d" fullword ascii
            $s9 = "[MEMORY] No files to write to Log.zip" fullword ascii
            $s10 = "VM Detection: Suspicious computer name detected" fullword ascii
            $s11 = "VM Detection: Blacklisted process detected" fullword ascii
            $s12 = "VM Detection: Timing anomaly detected" fullword ascii
            $s13 = "- NetBIOS: %s" fullword ascii
            $s14 = "- Language: %s" fullword ascii
            $s15 = "- CPU Vendor: %s" fullword ascii
            $s16 = "%s\\Clipboard.txt" fullword ascii
            
        condition:
            uint16(0) == 0x5A4D and $x1 and 7 of ($s*)
    }

IOCs:

  • SHA256: 26c3abc8bf32ff0f548adfa3c5fdf430c9bf061865512b83c4559553e668766c
  • File: C:\Users\admin\Desktop\Log.zip
  • Stealer panel: stealer.su

MITRE:

Technique ID Technique Name Evidence
T1059 Command and Scripting Interpreter Payload and modules executed from exported DLL functions (e.g., payload_main).
T1555.003 Credentials from Web Browsers Extracts browser passwords, cookies, autofill, and history.
T1552.004 Credentials: Private Keys Steals crypto wallet data and other stored private keys.
T1082 System Information Discovery Enumerates environment to collect target information for exfiltration.
T1497 Virtualization/Sandbox Evasion Anti-VM checks and execution delay to evade sandbox detection.
T1041 Exfiltration Over C2 Channel Splits collected ZIP archives and uploads over HTTP to hardcoded endpoints.
T1560.002 Archive via Library Uses in-memory ZIP creation for data compression before exfiltration.

Conclusion

1) Open-source RATs are becoming more accessible: Retro-C2’s open access and ready-made builder lower the entry barrier even for beginner attackers.

2) Diversification of delivery and execution techniques: Stealer-class threats demonstrate not only functional diversity but also flexibility in execution methods. The combination of multi-stage loaders, scripting interpreters, and modular architecture allows them to more effectively bypass protective mechanisms.

3) The MaaS model contributes to the evolution of threats: The rebranding of BluelineStealer to Santastealer and its public promotion reflect market mechanisms within the underground ecosystem, where competition stimulates the development of functionality.