logo

"Qealler" a new JAR-based Information Stealer

ID: 43f3fb67-e25b-5478-b323-b6b1be53a6ec

STIX ID: report--43f3fb67-e25b-5478-b323-b6b1be53a6ec

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes Qealler, a Proguard-obfuscated Java loader masquerading as invoice-related JARs that downloads encrypted modules (7z and qealler), extracts a Python-based credential stealer (QaZaqne/LaZagne), collects system and stored-credential data, encrypts it, and exfiltrates to multiple C2 endpoints; the document documents IOCs (domains, IPs, file hashes), infection mechanics, and payload unpacking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.