Decoding QBit Stealer: Source Release & Data Theft
ID: bb91d446-0149-58b6-abde-a51b0bff8052
STIX ID: report--bb91d446-0149-58b6-abde-a51b0bff8052
Feed Name: Cyble Blog
This report examines the public release of the qBit Stealer source code — a Go-based infostealer associated with the qBit RaaS — and details its operational features (anti-debug/Anti-VM checks, process discovery, configurable targeted file extensions, tar.gz archiving, chunked concurrent uploads to Mega.nz). The analysis highlights that the leak and the stealer's selective targeting make it attractive for use in ransomware double-extortion scenarios and increase the risk of wider adoption by lower-skilled threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
