Qealler Information Stealer
Qealler is a Java-based information stealer that uses the ProGuard obfuscator to evade detection and deploys a Python-based tool to steal credentials.
Summary
Qealler is a Java-based information stealer that uses the ProGuard obfuscator to evade detection and deploys a Python-based tool to steal credentials.
Affected platforms
The following platforms are known to be affected:
Threat details
Qealler is delivered via spam email. It is distributed as a JAR file and disguised as an invoice related document.
Once installed, Qealler will locate and extract credentials and system information from web browsers, mail clients, databases and memory dumps using a module called QaZagne. It will then encrypt all stolen information, using an AES cipher, before sending to a command and control server.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:53 pm