Qealler is a heavily obfuscated Java-based credential-stealing malware family that operates as a loader for a secondary harvesting component. It has also been referred to as Pyrogenic in some reporting, but Qealler is the more established name. The malware is typically delivered as socially engineered JAR files themed as invoices, remittances, or payment-related documents and relies on user execution for infection.
On Windows systems, the Java loader decrypts embedded configuration data and retrieves additional components from attacker-controlled infrastructure. Observed variants download a repackaged archive utility and a protected secondary payload, unpack the payload into temporary directories, and execute a bundled Python environment. The Python-stage harvester is a customized derivative of LaZagne, used to collect credentials from commonly used applications and Windows credential stores. Qealler also gathers host metadata such as operating system details, architecture, memory information, and in newer variants local and public IP information.
The malware encrypts collected data and exfiltrates it to command-and-control infrastructure over HTTP. Analysis of multiple variants indicates use of AES-based protection for configuration and payload handling, along with substantial obfuscation and encrypted Java classes to hinder reverse engineering. Some samples also query external services to determine the victim’s public IP address. Operationally, Qealler has been observed launching command interpreters and PowerShell, dropping supporting libraries during execution, and deleting temporary artifacts on shutdown through JVM shutdown hooks.
Code and configuration similarities across older Qealler and newer Pyrogenic-labeled samples indicate shared lineage, including common packer usage, overlapping cryptographic material, similar system-information schemas, and the same Python credential-harvesting approach. Reported targeting has included organizations in Australia, Africa, and the Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
cmd.exe /c chcp 1252 > NUL & powershell.exe -ExecutionPolicy Bypass -NoExit -NoProfile -Command -
cmd.exe /c chcp 1252 > NUL & powershell.exe -ExecutionPolicy Bypass -NoExit -NoProfile -Command -
After extraction, the main sample (Remittance.jar) executes a Python file of QaZagne (main.py) with the following option and takes the JSON output: %TEMP%\qealler\python\python.exe %TEMP%\qealler\qazaqne\main.py all
Qealler is heavily obfuscated Java based Infostealer... you will find many encrypted class files which don’t translate to Java src code.
Drop these two clean files sqlitejdbc.dll ... and jnidispatch.dll ... but it deletes these two file before exiting.
we can confirm that this sample uses the algo “AES/ECB/PKCS5Padding” and key may be generated using “PBKDF2WithHmacSHA1”
Connect to bot.whatismyipaddress.com to get the public IP of the infected system.
In this post we will be using a Java agent to dump the classes during runtime without any bytecode modification... Execute this command java -javaagent:dumper.jar -jar BankPaymAdviceVend_LLCRep.jar to run the malware with java agent and it will dump all the accessed classes at runtime
LaZagne is used to retrieve lots of passwords stored on a local computer. This is the same functionality of QaZagne, which finds and steals credentials of the most commonly used software from local machines.
It uses http://bot.whatismyipaddress.com for collecting the public IP of infected systems.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware discussed through comparison of older and newer variants. The content describes shared AES and UUID keys, collection of system information in JSON format, encryption and transmission to C2/CC, and use of a JVM shutdown hook to delete files.
A heavily obfuscated Java-based infostealer that connects to command-and-control infrastructure, retrieves the infected host's public IP, and steals credentials from different applications. The sample discussed uses layered obfuscation and encrypted class files, with AES/ECB/PKCS5Padding and PBKDF2WithHmacSHA1 referenced in its decryption routine.
A highly obfuscated Java-based loader that uses social engineering via malicious invoice-themed JAR files, downloads encrypted modules, extracts bundled 7-Zip and Python components, runs a credential-stealing Python module, collects system information and stored credentials, and exfiltrates the data to a C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.