"Qealler" a new JAR-based Information Stealer
ID: 43f3fb67-e25b-5478-b323-b6b1be53a6ec
STIX ID: report--43f3fb67-e25b-5478-b323-b6b1be53a6ec
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes Qealler, a Proguard-obfuscated Java loader masquerading as invoice-related JARs that downloads encrypted modules (7z and qealler), extracts a Python-based credential stealer (QaZaqne/LaZagne), collects system and stored-credential data, encrypts it, and exfiltrates to multiple C2 endpoints; the document documents IOCs (domains, IPs, file hashes), infection mechanics, and payload unpacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
