Researchers reported that Qealler, also tracked as Pyrogenic, operated as a heavily obfuscated Java-based infostealer delivered through socially engineered .jar files themed as invoices, remittances, and payment advice. The malware contacted attacker-controlled infrastructure, including 157.245.160[.]150:80, queried external services for the victim’s public IP, launched cmd.exe and PowerShell, dropped components such as sqlitejdbc.dll and jnidispatch.dll, and harvested credentials and host data from Windows systems before encrypting and exfiltrating the results. Analysis also found that the loader downloaded encrypted secondary components, unpacked a repackaged 7-Zip utility and a password-protected payload, and executed a bundled Python environment containing a customized credential stealer derived from LaZagne.
Separate reverse-engineering of older and newer samples found strong code-level continuity between Qealler and Pyrogenic variants, indicating shared development rather than unrelated malware. Both variants reportedly used the same Qrypter packer variant, the same AES key value, and the same UUID-related configuration key, while collecting system information in JSON format and using a JVM shutdown hook to delete files after execution. The newer sample added localIpAddress and globalIpAddress fields to the stolen host profile, and a memory artifact referencing QeallerV4.kotlin_module suggested the malware had evolved into a later version while retaining its original architecture and credential-theft workflow.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
The newer sample included the memory artifact string "QeallerV4.kotlin_module," which Securityinbits assessed may indicate the Pyrogenic/Qealler sample is version 4; the analysis also noted added localIpAddress and globalIpAddress fields in collected system information.
A follow-up comparison found the older Qealler sample and newer Pyrogenic/Qealler sample shared the same Qrypter packer variant, AES key bbb6fec5ebef0d93, UUID-related configuration key, JSON-based system information collection, and JVM shutdown-hook file deletion behavior.
Securityinbits concluded the sample used encrypted Java classes protected with AES/ECB/PKCS5Padding and likely PBKDF2WithHmacSHA1-derived keys, rather than a custom decryption algorithm.
During dynamic analysis, the sample contacted 157.245.160[.]150 over port 80, launched cmd.exe and PowerShell, dropped and later deleted sqlitejdbc.dll and jnidispatch.dll, queried bot.whatismyipaddress.com, and stole credentials from multiple applications.
Securityinbits analyzed a Java-based infostealer sample named BankPaymAdviceVend_LLCRep.jar (MD5 F0E21C7789CD57EEBF8ECDB9FADAB26B), describing Qealler/Pyrogenic as active in ANY.RUN submissions and reportedly targeting organizations in Australia, Africa, and the Middle East.
Zscaler analyzed Qealler as a heavily obfuscated Java loader that decrypted URLs, downloaded components from 82.196.11[.]96, unpacked a password-protected payload with bundled 7-Zip, executed a customized LaZagne-derived stealer, and exfiltrated encrypted system and credential data.
In January 2019, a Qealler campaign used invoice- and remittance-themed malicious JAR files distributed via compromised websites, including a Remittance.jar sample downloaded from hiexsgroup.co[.]uk.
Zscaler ThreatLabZ first observed the Qealler payload in Zscaler Cloud Sandbox on January 21, 2019, identifying a Java-based loader used to deliver a credential-harvesting payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securityinbits.com
Open sourcesecurityinbits.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.