Qealler
Aliases: Pyrogenic Infostealer
- First seen
- 2022-05-15 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-17 09:32:48
- Profile updated
- 2026-07-07 14:32:21
Targeted industries: financial-services technology-and-telecommunications
Context
Qealler, also known as Pyrogenic Infostealer, is a malware family that focuses on exfiltrating sensitive information such as credentials from infected systems. It is commonly used in cybercriminal operations targeting the financial and tech sectors.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Java_Pyrogenic (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Jar.Qealler (report)
- securityinbits.com — Unpacking Pyrogenic Qealler Using Java Agent Part 0X2 (report)
- herbiez.com (report)
- securityinbits.com — Similarity Between Qealler Pyrogenic Variants Part 0X3 (report)
- securityinbits.com — Pyrogenic Infostealer Static Analysis Part 0X1 (report)
- zscaler.com — Qealler New Jar Based Information Stealer (report)
- cyberark.com — Qealler The Silent Java Credential Thief (report)
- github.com — Qealler Unloaded (report)