Skip to content

QakBot

QakBot, also known as Qbot, Pinkslipbot, and QuackBot, is a Windows banking Trojan that evolved into an information-stealing malware family and loader for follow-on payloads.

Profile source: Mallory opens in a new tab

QakBot

Family profile

QakBot, also known as Qbot, Pinkslipbot, and QuackBot, is a Windows banking Trojan that evolved into an information-stealing malware family and loader for follow-on payloads. It collects host and security-product information, can steal credentials and email data, and has been used for reconnaissance and delivery of additional malware. QakBot supports persistence through mechanisms including scheduled tasks and BITS jobs, and can use process injection to evade detection. It has frequently served as an access and payload-delivery mechanism in ransomware intrusions, including incidents involving Cobalt Strike, Brute Ratel, and ransomware families such as Egregor, ProLock, Black Basta, and Conti. QakBot has been distributed through phishing email campaigns using social-engineering lures, including malicious Microsoft OneNote documents, password-protected archives, disk images, and script-based execution chains. TA577 has used OneNote-based phishing to distribute QakBot. The malware primarily targets Windows environments across multiple industries and geographies.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Reported operators

Threat actors

29 named in public reporting
TA577

TA577 returned from a month-long hiatus in activity and began using OneNote to deliver Qbot at the end of January 2023.

WIZARD SPIDER

"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"

Threat Group-3390

"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"

GOLD LAGOON

the financially motivated GOLD LAGOON threat group leverages the Qakbot botnet to deploy Cobalt Strike... The attachment downloaded and installed Qakbot. Qakbot profiled the infected host, sent the profiled data to its C2 servers, and then downloaded and executed Cobalt Strike Beacon.

Black Basta

In this latest campaign, the Black Basta ransomware gang is using QakBot malware to create an initial point of entry and move laterally within an organization’s network. QakBot, also known as QBot or Pinkslipbot, is a banking trojan primarily used to steal victims’ financial data, including browser information, keystrokes, and credentials.

Conti

Compromised servers are then used to spread phishing emails delivering Datoploader (aka Squirrelwaffle) and the QBot trojan.

TA551

QAKBOT (detected by Trend Micro as TrojanSpy.Win32.QAKBOT) is a modular and highly evasive information-stealing malware that was first discovered in 2007. This threat is also known as QBOT and PinkSlipbot.

TR

QAKBOT (detected by Trend Micro as TrojanSpy.Win32.QAKBOT) is a modular and highly evasive information-stealing malware that was first discovered in 2007. This threat is also known as QBOT and PinkSlipbot.

Water Minyades

The actors behind Water Minyades are known for delivering other malware during the last quarter of 2022, such as Qakbot, RaccoonStealer, and Bumbleloader via social engineering techniques.

TA570

Qakbot (aka QBot, QuakBot, and Pinkslipbot) is a sophisticated piece of malware that has been active since at least 2007. Since the end of January 2023, there has been an upsurge in the number of Qakbot campaigns using a novel delivery technique: OneNote documents for malware distribution.

GoldCabin

In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.

MALLARD SPIDER

In the last six months, there have been several reports of REvil ransomware deployment following an initial IcedID or Qakbot infection.

BlackCat

The FBI is investigating the Qakbot malicious software (“malware”) and its associated botnet. The Qakbot malware is controlled by a cybercriminal organization, and its operators and administrators use Qakbot to target critical industries worldwide.

ShadowSyndicate

...Watermark Связанные группы и кампании 426352781 ShadowSyndicate, ботнет Qakbot...

UNC4393

The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.

UNC2633

The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.

UNC2500

The group has overwhelmingly leveraged initial access gained via UNC2633 and UNC2500 QAKBOT botnet infections to deploy BASTA ransomware. QAKBOT is typically distributed via phishing emails containing malicious links or attachments.

DEV-0450

September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.

DEV-0506

September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.

DEV-0464

September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.

DEV-0826

September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.

DEV-0216

September 2022 update – New information about recent Qakbot campaigns leading to ransomware deployment. ... Another widely distributed malware, Qakbot, also leads to handoffs to RaaS affiliates.

Lockean

In most of the attacks described in the report, the threat actor gained initial access to the victim network through Qbot/QakBot, a banking trojan that changed its role to distribute other malware, including ransomware strains ProLock, Egregor, and DoppelPaymer.

Storm-1811

In several cases, Microsoft Threat Intelligence identified such activity leading to the download of Qakbot, RMM tools like ScreenConnect and NetSupport Manager, and Cobalt Strike. Qakbot has been used over the years as a remote access vector to deliver additional malicious payloads that led to ransomware deployment.

Vortex Werewolf

QakBot (Qbot/Quakbot) continues to operate well after the FBI's August 2023 "Operation Duck Hunt" takedown. Campaign tchk08, first observed February 2024, delivers QakBot via an MSI installer masquerading as Adobe Acrobat.

FIN7

In March 2023, CTU researchers observed an intrusion deploying Clop ransomware stemming from a Qakbot infection...

Storm-0506

"The threat actor gained initial access to the organization via Qakbot infection..."

TA542

Qbot affiliate id “partner01” is the primary payload dropped by Emotet seen almost daily.

Cardinal

“It also had a strong association with the Qakbot botnet, prior to its takedown in August 2023.”

Exploited software

Vulnerabilities linked to QakBot

16 CVEs

MITRE ATT&CK

QakBot in ATT&CK

121 distinct techniques

Techniques

121 techniques
T1567.002 Exfiltration to Cloud Storage T1048 Exfiltration Over Alternative Protocol T1059.005 Visual Basic T1518.001 Security Software Discovery T1082 System Information Discovery T1036.007 Double File Extension T1027 Obfuscated Files or Information T1053.005 Scheduled Task T1197 BITS Jobs T1049 System Network Connections Discovery T1071.001 Web Protocols T1105 Ingress Tool Transfer T1218.011 Rundll32 T1586 Compromise Accounts T1059.001 PowerShell T1204.002 Malicious File T1018 Remote System Discovery T1033 System Owner/User Discovery T1135 Network Share Discovery T1204 User Execution T1016 System Network Configuration Discovery T1566.001 Spearphishing Attachment T1071 Application Layer Protocol T1486 Data Encrypted for Impact T1560 Archive Collected Data T1112 Modify Registry T1583 Acquire Infrastructure T1069.001 Local Groups T1566.003 Spearphishing via Service T1027.006 HTML Smuggling T1566 Phishing T1566.002 Spearphishing Link T1059.003 Windows Command Shell T1059 Command and Scripting Interpreter T1046 Network Service Discovery T1203 Exploitation for Client Execution T1036 Masquerading T1498 Network Denial of Service T1078.001 Default Accounts T1564 Hide Artifacts T1218.005 Mshta T1574.001 DLL T1059.007 JavaScript T1218 System Binary Proxy Execution T1055 Process Injection T1216.001 PubPrn T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1027.002 Software Packing T1110 Brute Force T1003 OS Credential Dumping T1555.003 Credentials from Web Browsers T1132 Data Encoding T1057 Process Discovery T1059.004 Unix Shell T1218.010 Regsvr32 T1083 File and Directory Discovery T1055.012 Process Hollowing T1547.001 Registry Run Keys / Startup Folder T1568.002 Domain Generation Algorithms T1562 Impair Defenses T1564.001 Hidden Files and Directories T1005 Data from Local System T1573 Encrypted Channel T1070.004 File Deletion T1027.005 Indicator Removal from Tools T1106 Native API T1555 Credentials from Password Stores T1041 Exfiltration Over C2 Channel T1124 System Time Discovery T1047 Windows Management Instrumentation T1090 Proxy T1056 Input Capture T1053 Scheduled Task/Job T1482 Domain Trust Discovery T1568 Dynamic Resolution T1021 Remote Services T1069 Permission Groups Discovery T1114 Email Collection T1539 Steal Web Session Cookie T1562.001 Disable or Modify Tools T1497.001 System Checks T1219 Remote Access Tools T1570 Lateral Tool Transfer T1543 Create or Modify System Process T1210 Exploitation of Remote Services T1090.003 Multi-hop Proxy T1548 Abuse Elevation Control Mechanism T1078 Valid Accounts T1562.004 Disable or Modify System Firewall T1132.001 Standard Encoding T1027.007 Dynamic API Resolution T1003.001 LSASS Memory T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1622 Debugger Evasion T1012 Query Registry T1095 Non-Application Layer Protocol T1010 Application Window Discovery T1559.001 Component Object Model T1190 Exploit Public-Facing Application T1586.002 Email Accounts T1189 Drive-by Compromise T1071.004 DNS T1129 Shared Modules T1185 Browser Session Hijacking T1007 System Service Discovery T1202 Indirect Command Execution T1553.005 Mark-of-the-Web Bypass T1021.005 VNC T1543.003 Windows Service T1087 Account Discovery T1565 Data Manipulation T1091 Replication Through Removable Media T1620 Reflective Code Loading T1547.009 Shortcut Modification T1537 Transfer Data to Cloud Account T1649 Steal or Forge Authentication Certificates T1056.001 Keylogging T1598 Phishing for Information T1055.001 Dynamic-link Library Injection T1068 Exploitation for Privilege Escalation

Reporting

Research mentioning QakBot

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 11
Cvefeed High Severity

CVE-2026-62781 - RPC Runtime Library Remote Code Execution Vulnerability

Microsoft disclosed CVE-2026-62781, a high-severity remote code execution flaw in the Windows RPC Runtime Library that allows an unauthenticated attacker to execute code over the network. The heap-based buffer overflow, tracked as CWE-122 and scored CVSS 8.1, affects a broad range of Windows client and server platforms, including Windows 10, Windows 11, and Windows Server 2012, 2016, 2019, 2022, and 2025, according to the CVE entry and Microsoft advisory. The exposure is notable because exploitation of remote services has repeatedly enabled rapid lateral movement and internal propagation across Windows environments. MITRE ATT&CK maps this activity to T1210, citing past abuse of SMB, Netlogon, RPC, and Print Spooler flaws by threats such as WannaCry, NotPetya, TrickBot, Conficker, and multiple intrusion groups; Splunk has also tied remote-service exploitation detections to the same technique in prior RCE-related content. Security teams are likely to treat the new RPC flaw as a priority patching issue given its network-reachable nature and the history of Windows remote-service vulnerabilities being used for enterprise-wide spread.

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 21
Security Online Info

TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed

Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.