SoupDealer is a Java-based malware family described in the provided content as a loader and also as a stealer, active in campaigns targeting Turkish users and organizations in Türkiye, including banks, ISPs, and organizations in the financial and industrial sectors. It was documented by security vendors in August 2025. Delivery is associated with phishing campaigns and trojanized installers, with malicious JAR files disguised as invoices or proposals; an example filename given is TEKLIFALINACAKURUNLER.jar. Execution occurs via java.exe or javaw.exe. The malware uses custom class loaders and defineClass to decrypt and load follow-on payloads directly into memory, with onion command-and-control endpoints hidden in memory. The content states that SoupDealer routes C2 traffic exclusively through Tor and validates Tor bootstrap connectivity using check.torproject.org. Persistence is established through randomly named Scheduled Tasks or Run registry keys that mimic Microsoft or Office updates; one cited example is a Scheduled Task named OfficeUpdate_6f3a. Reported behaviors include suspicious Java execution from user-writable paths, Tor-related network activity including ports 9050 and 9150, and persistence creation. The content notes that SoupDealer shares some traits with Gootloader and BumbleBee but is distinguished by Tor reliance and memory-only execution. No specific threat actor attribution is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Java-based loader delivered via phishing or trojanized installers, executed through java.exe/javaw.exe, using custom class loaders to decrypt and load follow-on payloads directly into memory. It establishes persistence via Scheduled Tasks or Run keys and routes C2 traffic through Tor.
Stealthy Java-based loader used in phishing campaigns, likely to deliver additional malware payloads.
SoupDealer is a Java-based loader malware used in phishing campaigns targeting Turkish organizations. It establishes persistence, uses TOR for C2 communication, and allows attackers full control over infected devices.
Java-based information stealer malware used in campaigns targeting Turkish users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.