TL;DR

  • BQTLock (Ransomware-as-a-Service): Ransomware-as-a-service with the main goal of financial gain, delivered with RAT malware like REMCOS as a stager. It tries to make its actions invisible and is also used for data theft.
  • Upstage (Infostealer/Proxyware): Multifunctional malware combining infostealer and proxy-bot capabilities, distributed via the Malware-as-a-Service (MaaS) model through SEO poisoning and malvertising. Masquerades as legitimate software like 7-Zip.
  • XillenStealer (Python Stealer): Professional cross-platform Python stealer for exfiltrating sensitive information. Uses an Electron interface for building payloads and supports integration with Telegram.

1) BQTLock (Windows)

Sample: ANY.RUN

BQTLock is ransomware-as-a-service with the main goal of financial gain.

How to detect: Detected by monitoring anomalous activity with files and command lines.

Key facts:

  • BQTLock is RAAS that comes with RAT malware like REMCOS as its stager.
  • It tries to make its actions invisible.
  • It is also used for data theft.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-01-22 News 2026-01-22 0

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"\\bqt_" OR commandLine:"\\BQTLock_"

IOCs:

  • SHA256: 4437ab9c5db3c5ebb9235b4adade504153fa39ca5774ac8c6145a0b7c97a97eb
  • SHA256: dd381ad3ecc0f0c6a13a1c8c8f7c3db18f6ce9edf01da3b6b2fdcc2de1030697
  • SHA256: 58c245451bb8f366a4493593e8e285f4d6c71868630b7bf118527370726c3b7b
  • SHA256: a0a2352463492d6003cc0a49402ec75536e2b8d7cea3dd3705fbf3c6c9b75262
  • SHA256: edfc349f8127c88ba3221a93bc037778a9bf484db01152f42cd2348d9382d94d
  • SHA256: c56c7da821158cb45f3224bfd75d2351ed8eb3ebc5dc3dfa3090a43a3852b80d
  • SHA256: 37568589d2511356a30dc7d4230da375f826871033a8e84e10f2b819275a067a
  • SHA256: de4dfba123806e40028e905409d77f2bfc2deee574a140ebf14f3a9e6311e09f
  • SHA256: b3f99baed0267e81076b9da45c546c62da91c1b771700d5717fb4d487692db27
  • SHA256: d3a2fa3e1f6e0ba58be8254444cb7fee7be3b9c10cc1b6d3ffc5a051cac0d573
  • SHA256: 97d71c129b4a372d8a759785b6e6c2ba0777b3b521ee383088e8aba6c0e6c5e0

MITRE:

Technique ID Technique Name Evidence
T1053.005 Scheduled Task/Job: Scheduled Task Uses Task Scheduler to autorun other applications
T1112 Modify Registry Delegate execute modification
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control Bypass User Account Control (fodhelper)
T1497.003 Virtualization/Sandbox Evasion: Time Based Checks Uses Task Scheduler to autorun other applications
T1552.001 Unsecured Credentials: Credentials In Files Steals credentials from Web Browsers
T1555.003 Credentials from Password Stores: Credentials from Web Browsers Steals credentials from Web Browsers
T1486 Data Encrypted for Impact Encrypts files on the system

2) Upstage (Windows)

Sample: ANY.RUN

Upstage is multifunctional malware combining the capabilities of an infostealer and a proxy-bot (proxyware). Distributed via the Malware-as-a-Service (MaaS) model, masquerading as legitimate system software such as the 7-Zip archiver, through SEO poisoning mechanisms and malicious advertising (malvertising). The main goal of the malware is to steal browser credentials, messenger sessions, cryptocurrency wallet data, as well as using the resources of the infected node as a proxy server.

How to detect: Detection of Upstage is based on identifying specific behavioral patterns and artifacts in the file system.

Key facts:

  • Upstage uses a unique hidden presence architecture focused on bypassing network restrictions and masquerading as system processes.
  • Placement of executable files in the SysWOW64 directory, mimicking system components in 64-bit OS.
  • To execute the main malicious code, Upstage often relies on DLL Side-Loading, loading the malicious hero.dll library through a trusted process.
  • In addition, Upstage checks the environment for debugging tools and virtualization, allowing it to evade automated analysis in sandboxes.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-01-26 News 2026-01-27 28

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"C:\\Windows\\SysWOW64\\hero\\hero.exe" OR filePath:"C:\\Windows\\SysWOW64\\hero\\Uphero.exe"

IOCs:

  • SHA256: 408a89bc9966e76f3a192ecbf47b36fdc8ddaa4067aaee753c0bd6ae502f5cea
  • SHA256: 78acb25594c6e333cefb523efbabb498ec7b6f66aa868241a2f55b03285c9824
  • SHA256: a7d387a5e238a5c8c97f3145c48363a1db52e55480d95566c112c4649c6c3b2e
  • DOMAIN: soc.hero-sms.co
  • DOMAIN: neo.herosms.co
  • DOMAIN: flux.smshero.co
  • DOMAIN: nova.smshero.ai
  • DOMAIN: zest.hero-sms.ai
  • DOMAIN: apex.herosms.ai
  • DOMAIN: mint.smshero.com
  • DOMAIN: vivid.smshero.vip
  • DOMAIN: spark.herosms.io
  • DOMAIN: prime.herosms.vip
  • DOMAIN: glide.smshero.cc
  • DOMAIN: pulse.herosms.cc

MITRE:

Technique ID Technique Name Evidence
T1562.004 Impair Defenses: Disable or Modify System Firewall Manipulation of the firewall via netsh to create allowing rules for the "Uphero" and "hero" modules.
T1036.005 Masquerading: Match Legitimate Name or Location Placement of files in the system folder *C:\Windows\SysWOW64\hero* to imitate legitimate software.
T1574.002 Hijack Execution Flow: DLL Side-Loading Loading the payload via the malicious hero.dll library in the same folder as the EXE file.
T1090.003 Proxy: Multi-hop Proxy Use of the infected host as a proxy network node (according to the proxyware category).
T1583.008 Resource Development: Malvertising Use of malicious advertising and fake 7-Zip sites for initial victim attraction.
T1204.002 User Execution: Malicious File Launching the infection chain via a fake installer 7z2408-x64.exe.
T1555.003 Credentials from Web Browsers Mass theft of saved passwords, card data, and profiles from browsers of the Chromium and Gecko families.
T1539 Steal Web Session Cookie Collection of session cookies for account capture without the need for password entry and 2FA.
T1071.001 Application Layer Protocol: Web Protocols Use of HTTP/HTTPS for transmitting encrypted data archives to the C2 server.
T1497.001 Virtualization/Sandbox Evasion: System Checks Checking the environment for signs of virtualization and analysis tools before activation.

3) XillenStealer (Python)

Sample: ANY.RUN

XillenStealer is a cross-platform Python stealer designed for exfiltrating sensitive information from end-user systems. It uses an Electron interface for building payloads and supports extensive configuration, including integration with Telegram for automated data exfiltration. The architecture is highly modular and object-oriented, offering anti-analysis features and sandbox evasion.

How to detect: Detected via YARA rule or behavioral patterns.

Key facts:

  • Easy builder for everyone: Comes with a public GUI builder that allows low-skilled attackers to quickly generate a working payload.
  • Extremely broad data collection: Steals from over 100 browsers, more than 70 crypto wallets, password managers, messenger tokens, cloud configs, DevOps tools, and more.
  • Strong anti-analysis and hidden exfiltration: Uses polymorphism, obfuscation, VM checks, and sends stolen data via Telegram bots or cloud channels to avoid detection.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2025-11-25 News 2025-05-12 7

Yara

rule xillen_stealer {
    meta:
        author = "ANY.RUN"
        family = "xillen"
        tags = "xillen, stealer"

              
    strings:
        $x1 = "t.me/Xillen_Adapter" ascii
        $x2 = "github.com/BengaminButton" ascii
        $x3 = "Xillen Killers" ascii
        $x5 = "XillenStealer" ascii
     

        $s1 = "EXTRA_FEATURES"  ascii
        $s2 = "check_vm_sandbox" ascii
        $s3 = "vm_mac_prefixes" ascii
        $s4 = "TG_CHAT_ID" ascii
        $s5 = "PAYLOAD_START" ascii
        $s6 = "Steam Guard files found" ascii
        $s7 = "wallet\\passphrase.json" ascii
        $s8 = "GeroWallet (Cardano)" ascii
        $s9 = "=== MESSENGERS" ascii
        $s10 = "=== DISCORD" ascii
        $s11 = "GAME ACCOUNTS" ascii
     
    condition:
        (uint16(0) == 0x5A4D or uint32(0) == 0x464c457f) and 
        1 of ($x*) and 2 of ($s*)
}

MITRE:

Technique ID Technique Name Evidence
T1204 User Execution XillenStealer requires the user to run the downloaded Python-based executable or installer.
T1059 Command and Scripting Interpreter Uses Python scripts to execute modules and perform data collection.
T1053.005 Scheduled Task/Job Creates hidden Windows scheduled tasks for persistence.
T1055 Process Injection Injects into explorer.exe or other system processes to evade detection.
T1497 Virtualization/Sandbox Evasion Detects VM or sandbox environments to avoid analysis.
T1555.003 Credential Dumping: Password Stores Extracts passwords, cookies, autofill, and history from 100+ browsers.
T1555.004 Credential Dumping: Password Managers Retrieves credentials from LastPass, 1Password, Bitwarden, Dashlane.
T1113 Screen Capture Captures screenshots of the desktop.
T1082 System Information Discovery Gathers CPU, RAM, GPU, disks, OS, architecture, hostname, MAC addresses.
T1046 Network Service Discovery Collects IP addresses, hostnames, MAC addresses.
T1071.001 Application Layer Protocol: Web Protocols Exfiltrates stolen data to Telegram bots using API.
T1531 Account Access / Credential Theft Steals crypto wallets, social media tokens, and messaging credentials.
T1078 Valid Accounts Obtained credentials allow access to Discord, Steam, Telegram, and other accounts.

Conclusion

1) Ransomware uses RATs for staging: BQTLock is delivered with RATs like REMCOS, which allows hiding actions and stealing data before encryption.

2) Proxy in system folders: Upstage hides proxyware in SysWOW64, configuring the firewall via netsh, turning an ordinary PC into a node in someone else's network.

3) Builder for beginners: XillenStealer with a GUI-builder simplifies payload-generation for attackers.