ZStealer
Aliases: Z*Stealer
- First seen
- 2021-07-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 13:04:41
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
ZStealer is an information stealer malware commonly used by the cybercrime group Void Balaur. It is primarily aimed at stealing credentials and sensitive data from targeted industries.
Detection coverage
- 1 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Zstealer_Nov_2021_1 (yara-rule)
Reports & references
- Trend Micro — Wp Void Balaur Tracking A Cybermercenarys Activities (report)
- twitter.com — 1458973883068043264 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zstealer (report)