ZStealer

Aliases: Z*Stealer

First seen
2021-07-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 13:04:41

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

ZStealer is an information stealer malware commonly used by the cybercrime group Void Balaur. It is primarily aimed at stealing credentials and sensitive data from targeted industries.

Detection coverage

  • 1 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Zstealer_Nov_2021_1 (yara-rule)

Reports & references

  • Trend Micro — Wp Void Balaur Tracking A Cybermercenarys Activities (report)
  • twitter.com — 1458973883068043264 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Zstealer (report)

External references