TA577 returned from a month-long hiatus in activity and began using OneNote to deliver Qbot at the end of January 2023.
QakBot
QakBot, also known as Qbot, Pinkslipbot, and QuackBot, is a Windows banking Trojan that evolved into an information-stealing malware family and loader for follow-on payloads.
Profile source: Mallory opens in a new tabQakBot
Family profile
QakBot, also known as Qbot, Pinkslipbot, and QuackBot, is a Windows banking Trojan that evolved into an information-stealing malware family and loader for follow-on payloads. It collects host and security-product information, can steal credentials and email data, and has been used for reconnaissance and delivery of additional malware. QakBot supports persistence through mechanisms including scheduled tasks and BITS jobs, and can use process injection to evade detection. It has frequently served as an access and payload-delivery mechanism in ransomware intrusions, including incidents involving Cobalt Strike, Brute Ratel, and ransomware families such as Egregor, ProLock, Black Basta, and Conti. QakBot has been distributed through phishing email campaigns using social-engineering lures, including malicious Microsoft OneNote documents, password-protected archives, disk images, and script-based execution chains. TA577 has used OneNote-based phishing to distribute QakBot. The malware primarily targets Windows environments across multiple industries and geographies.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
- Reconnaissance
Reported operators
Threat actors
29 named in public reporting"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
the financially motivated GOLD LAGOON threat group leverages the Qakbot botnet to deploy Cobalt Strike... The attachment downloaded and installed Qakbot. Qakbot profiled the infected host, sent the profiled data to its C2 servers, and then downloaded and executed Cobalt Strike Beacon.
In this latest campaign, the Black Basta ransomware gang is using QakBot malware to create an initial point of entry and move laterally within an organization’s network. QakBot, also known as QBot or Pinkslipbot, is a banking trojan primarily used to steal victims’ financial data, including browser information, keystrokes, and credentials.
Compromised servers are then used to spread phishing emails delivering Datoploader (aka Squirrelwaffle) and the QBot trojan.
QAKBOT (detected by Trend Micro as TrojanSpy.Win32.QAKBOT) is a modular and highly evasive information-stealing malware that was first discovered in 2007. This threat is also known as QBOT and PinkSlipbot.
QAKBOT (detected by Trend Micro as TrojanSpy.Win32.QAKBOT) is a modular and highly evasive information-stealing malware that was first discovered in 2007. This threat is also known as QBOT and PinkSlipbot.
The actors behind Water Minyades are known for delivering other malware during the last quarter of 2022, such as Qakbot, RaccoonStealer, and Bumbleloader via social engineering techniques.
Qakbot (aka QBot, QuakBot, and Pinkslipbot) is a sophisticated piece of malware that has been active since at least 2007. Since the end of January 2023, there has been an upsurge in the number of Qakbot campaigns using a novel delivery technique: OneNote documents for malware distribution.
In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.
In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.
The FBI is investigating the Qakbot malicious software (“malware”) and its associated botnet. The Qakbot malware is controlled by a cybercriminal organization, and its operators and administrators use Qakbot to target critical industries worldwide.
...Watermark Связанные группы и кампании 426352781 ShadowSyndicate, ботнет Qakbot...
The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.
The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.
The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.
September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.
September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.
September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.
September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.
September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.
In most of the attacks described in the report, the threat actor gained initial access to the victim network through Qbot/QakBot, a banking trojan that changed its role to distribute other malware, including ransomware strains ProLock, Egregor, and DoppelPaymer.
In several cases, Microsoft Threat Intelligence identified such activity leading to the download of Qakbot, RMM tools like ScreenConnect and NetSupport Manager, and Cobalt Strike. Qakbot has been used over the years as a remote access vector to deliver additional malicious payloads that led to ransomware deployment.
QakBot (Qbot/Quakbot) continues to operate well after the FBI's August 2023 "Operation Duck Hunt" takedown. Campaign tchk08, first observed February 2024, delivers QakBot via an MSI installer masquerading as Adobe Acrobat.
In March 2023, CTU researchers observed an intrusion deploying Clop ransomware stemming from a Qakbot infection...
"The threat actor gained initial access to the organization via Qakbot infection..."
Qbot affiliate id “partner01” is the primary payload dropped by Emotet seen almost daily.
“It also had a strong association with the Qakbot botnet, prior to its takedown in August 2023.”
Exploited software
Vulnerabilities linked to QakBot
16 CVEsMITRE ATT&CK
QakBot in ATT&CK
121 distinct techniquesTechniques
121 techniquesReporting
Research mentioning QakBot
GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
CVE-2026-62781 - RPC Runtime Library Remote Code Execution Vulnerability
Microsoft disclosed CVE-2026-62781, a high-severity remote code execution flaw in the Windows RPC Runtime Library that allows an unauthenticated attacker to execute code over the network. The heap-based buffer overflow, tracked as CWE-122 and scored CVSS 8.1, affects a broad range of Windows client and server platforms, including Windows 10, Windows 11, and Windows Server 2012, 2016, 2019, 2022, and 2025, according to the CVE entry and Microsoft advisory. The exposure is notable because exploitation of remote services has repeatedly enabled rapid lateral movement and internal propagation across Windows environments. MITRE ATT&CK maps this activity to T1210, citing past abuse of SMB, Netlogon, RPC, and Print Spooler flaws by threats such as WannaCry, NotPetya, TrickBot, Conficker, and multiple intrusion groups; Splunk has also tied remote-service exploitation detections to the same technique in prior RCE-related content. Security teams are likely to treat the new RPC flaw as a priority patching issue given its network-reachable nature and the history of Windows remote-service vulnerabilities being used for enterprise-wide spread.
Post by @lazarusholic.bsky.social - Bluesky
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Exposing FakeBat loader: distribution methods and adversary infrastructure
TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed
Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.