QakBot
Also known as: Oakboat, Pinkslipbot, Qbot, Quakbot
QBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active for years since 2007. It has historically been known as a banking Trojan, meaning that it steals financial data from infected systems, and a loader using C2 servers for payload targeting and download.
Linked Threat Actors
C2 Infrastructure
Last 7 days
| Date | C2 Hosts |
|---|---|
| May 8, 2026 | 147 |
Further Reading
Explore expert insights on secure communications from BlackBerry — covering government, critical infrastructure, resilience, compliance, and trusted communications at scale.
More interesting and practical queries for identifying malware infrastructure.
More interesting and practical queries for identifying malware infrastructure.
A packing software called CryptOne became popular recently among some major threat actors. It was first reported by Fox-IT.
Microsoft coined the term “human-operated ransomware” to clearly define a class of attack driven by expert human intelligence at every step of the attack chain and culminate in intentional business...
If you see any of these malware strains on your enterprise networks, stop everything you're doing and audit all systems.
Zscaler ThreatLabz team observed multiple OneNote malware campaign spreading RATs, Bankers, and Stealer category malware with multi-layer obfuscation.