TL;DR

Sample: ANY.RUN
BQTLock is ransomware-as-a-service with the main goal of financial gain.
How to detect: Detected by monitoring anomalous activity with files and command lines.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-01-22 | News | 2026-01-22 | 0 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"\\bqt_" OR commandLine:"\\BQTLock_"
IOCs:
4437ab9c5db3c5ebb9235b4adade504153fa39ca5774ac8c6145a0b7c97a97ebdd381ad3ecc0f0c6a13a1c8c8f7c3db18f6ce9edf01da3b6b2fdcc2de103069758c245451bb8f366a4493593e8e285f4d6c71868630b7bf118527370726c3b7ba0a2352463492d6003cc0a49402ec75536e2b8d7cea3dd3705fbf3c6c9b75262edfc349f8127c88ba3221a93bc037778a9bf484db01152f42cd2348d9382d94dc56c7da821158cb45f3224bfd75d2351ed8eb3ebc5dc3dfa3090a43a3852b80d37568589d2511356a30dc7d4230da375f826871033a8e84e10f2b819275a067ade4dfba123806e40028e905409d77f2bfc2deee574a140ebf14f3a9e6311e09fb3f99baed0267e81076b9da45c546c62da91c1b771700d5717fb4d487692db27d3a2fa3e1f6e0ba58be8254444cb7fee7be3b9c10cc1b6d3ffc5a051cac0d57397d71c129b4a372d8a759785b6e6c2ba0777b3b521ee383088e8aba6c0e6c5e0MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1053.005 | Scheduled Task/Job: Scheduled Task | Uses Task Scheduler to autorun other applications |
| T1112 | Modify Registry | Delegate execute modification |
| T1548.002 | Abuse Elevation Control Mechanism: Bypass User Account Control | Bypass User Account Control (fodhelper) |
| T1497.003 | Virtualization/Sandbox Evasion: Time Based Checks | Uses Task Scheduler to autorun other applications |
| T1552.001 | Unsecured Credentials: Credentials In Files | Steals credentials from Web Browsers |
| T1555.003 | Credentials from Password Stores: Credentials from Web Browsers | Steals credentials from Web Browsers |
| T1486 | Data Encrypted for Impact | Encrypts files on the system |

Sample: ANY.RUN
Upstage is multifunctional malware combining the capabilities of an infostealer and a proxy-bot (proxyware). Distributed via the Malware-as-a-Service (MaaS) model, masquerading as legitimate system software such as the 7-Zip archiver, through SEO poisoning mechanisms and malicious advertising (malvertising). The main goal of the malware is to steal browser credentials, messenger sessions, cryptocurrency wallet data, as well as using the resources of the infected node as a proxy server.
How to detect: Detection of Upstage is based on identifying specific behavioral patterns and artifacts in the file system.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2026-01-26 | News | 2026-01-27 | 28 |
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"C:\\Windows\\SysWOW64\\hero\\hero.exe" OR filePath:"C:\\Windows\\SysWOW64\\hero\\Uphero.exe"
IOCs:
408a89bc9966e76f3a192ecbf47b36fdc8ddaa4067aaee753c0bd6ae502f5cea78acb25594c6e333cefb523efbabb498ec7b6f66aa868241a2f55b03285c9824a7d387a5e238a5c8c97f3145c48363a1db52e55480d95566c112c4649c6c3b2esoc.hero-sms.coneo.herosms.coflux.smshero.conova.smshero.aizest.hero-sms.aiapex.herosms.aimint.smshero.comvivid.smshero.vipspark.herosms.ioprime.herosms.vipglide.smshero.ccpulse.herosms.ccMITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1562.004 | Impair Defenses: Disable or Modify System Firewall | Manipulation of the firewall via netsh to create allowing rules for the "Uphero" and "hero" modules. |
| T1036.005 | Masquerading: Match Legitimate Name or Location | Placement of files in the system folder *C:\Windows\SysWOW64\hero* to imitate legitimate software. |
| T1574.002 | Hijack Execution Flow: DLL Side-Loading | Loading the payload via the malicious hero.dll library in the same folder as the EXE file. |
| T1090.003 | Proxy: Multi-hop Proxy | Use of the infected host as a proxy network node (according to the proxyware category). |
| T1583.008 | Resource Development: Malvertising | Use of malicious advertising and fake 7-Zip sites for initial victim attraction. |
| T1204.002 | User Execution: Malicious File | Launching the infection chain via a fake installer 7z2408-x64.exe. |
| T1555.003 | Credentials from Web Browsers | Mass theft of saved passwords, card data, and profiles from browsers of the Chromium and Gecko families. |
| T1539 | Steal Web Session Cookie | Collection of session cookies for account capture without the need for password entry and 2FA. |
| T1071.001 | Application Layer Protocol: Web Protocols | Use of HTTP/HTTPS for transmitting encrypted data archives to the C2 server. |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | Checking the environment for signs of virtualization and analysis tools before activation. |

Sample: ANY.RUN
XillenStealer is a cross-platform Python stealer designed for exfiltrating sensitive information from end-user systems. It uses an Electron interface for building payloads and supports extensive configuration, including integration with Telegram for automated data exfiltration. The architecture is highly modular and object-oriented, offering anti-analysis features and sandbox evasion.
How to detect: Detected via YARA rule or behavioral patterns.
Key facts:
Analytical note:
| Detected | External sources | ANY.RUN Last Submission | Sandbox Evasion |
|---|---|---|---|
| 2025-11-25 | News | 2025-05-12 | 7 |
Yara
rule xillen_stealer {
meta:
author = "ANY.RUN"
family = "xillen"
tags = "xillen, stealer"
strings:
$x1 = "t.me/Xillen_Adapter" ascii
$x2 = "github.com/BengaminButton" ascii
$x3 = "Xillen Killers" ascii
$x5 = "XillenStealer" ascii
$s1 = "EXTRA_FEATURES" ascii
$s2 = "check_vm_sandbox" ascii
$s3 = "vm_mac_prefixes" ascii
$s4 = "TG_CHAT_ID" ascii
$s5 = "PAYLOAD_START" ascii
$s6 = "Steam Guard files found" ascii
$s7 = "wallet\\passphrase.json" ascii
$s8 = "GeroWallet (Cardano)" ascii
$s9 = "=== MESSENGERS" ascii
$s10 = "=== DISCORD" ascii
$s11 = "GAME ACCOUNTS" ascii
condition:
(uint16(0) == 0x5A4D or uint32(0) == 0x464c457f) and
1 of ($x*) and 2 of ($s*)
}
MITRE:
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1204 | User Execution | XillenStealer requires the user to run the downloaded Python-based executable or installer. |
| T1059 | Command and Scripting Interpreter | Uses Python scripts to execute modules and perform data collection. |
| T1053.005 | Scheduled Task/Job | Creates hidden Windows scheduled tasks for persistence. |
| T1055 | Process Injection | Injects into explorer.exe or other system processes to evade detection. |
| T1497 | Virtualization/Sandbox Evasion | Detects VM or sandbox environments to avoid analysis. |
| T1555.003 | Credential Dumping: Password Stores | Extracts passwords, cookies, autofill, and history from 100+ browsers. |
| T1555.004 | Credential Dumping: Password Managers | Retrieves credentials from LastPass, 1Password, Bitwarden, Dashlane. |
| T1113 | Screen Capture | Captures screenshots of the desktop. |
| T1082 | System Information Discovery | Gathers CPU, RAM, GPU, disks, OS, architecture, hostname, MAC addresses. |
| T1046 | Network Service Discovery | Collects IP addresses, hostnames, MAC addresses. |
| T1071.001 | Application Layer Protocol: Web Protocols | Exfiltrates stolen data to Telegram bots using API. |
| T1531 | Account Access / Credential Theft | Steals crypto wallets, social media tokens, and messaging credentials. |
| T1078 | Valid Accounts | Obtained credentials allow access to Discord, Steam, Telegram, and other accounts. |
1) Ransomware uses RATs for staging: BQTLock is delivered with RATs like REMCOS, which allows hiding actions and stealing data before encryption.
2) Proxy in system folders: Upstage hides proxyware in SysWOW64, configuring the firewall via netsh, turning an ordinary PC into a node in someone else's network.
3) Builder for beginners: XillenStealer with a GUI-builder simplifies payload-generation for attackers.