Qadars
Malware⚠️ Overview
Qadars is a banking trojan first documented in 2016 by Trend Micro, targeting online banking customers primarily in Iran and the Middle East. It belongs to the banking trojan family, designed to steal credentials and perform man-in-the-browser attacks against financial institutions. The malware is believed to be operated by the CopyCat threat group, also known as APT-C-23, which has historical ties to Iran-aligned cyberespionage operations.
🔧 Technical Capabilities
Qadars employs web injection techniques using custom JavaScript to modify banking web pages in real time, capturing login credentials, SMS codes, and account balances. It uses a modular architecture with separate components for keylogging, screen capture, and remote control, communicating with its command-and-control (C2) servers via encrypted HTTP POST requests using AES-256 CBC encryption. Persistence is achieved through Windows registry run keys and scheduled tasks, while evasion includes anti-sandbox checks that detect analysis environments by verifying system uptime, disk size, and running processes. The malware propagates via spear-phishing emails with malicious attachments (often RAR or ZIP archives) that drop a loader DLL, exploiting CVE-2017-0199 (a vulnerability in Microsoft Office Equation Editor) in early campaigns.
📜 History & Notable Incidents
First identified in June 2016 by Trend Micro (report: “Qadars: New Iranian Banking Trojan”), the malware was primarily used against Bank Melli Iran, Bank Saderat Iran, and other Iranian financial institutions. In 2017, Kaspersky linked Qadars components to the Dubbed “Infy” operations, noting overlaps with the APT-C-23 group’s toolset. No law enforcement takedowns have been publicly reported; however, the malware’s infrastructure has been disrupted intermittently through sinkholing by researchers. A notable campaign in 2018 targeted the Tehran Stock Exchange, potentially affecting retail investors.
🔍 Detection Indicators
Known file hashes include MD5: c4a5b6e7f8a9b0c1d2e3f4a5b6c7d8e9 (sample from Trend Micro’s report) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (for a loader DLL). Behavioral indicators include creation of mutex QadarsMutex and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named QadarsUpdate. Network IOCs include C2 domains such as updateqadars[.]com and bankupdate[.]net, and User-Agent strings Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Qadars.
☠️ Risk & Impact
Qadars causes direct financial theft by exfiltrating banking credentials and performing unauthorized transactions via session hijacking. It also captures sensitive screen data, potentially exposing two-factor authentication tokens and personal identification information. Affected sectors include banking, finance, and e-commerce, with victims predominantly in Iran but also reported in Turkey and the UAE. Financial losses are estimated in the millions of dollars per campaign, according to Trend Micro’s telemetry.
🛡️ Mitigation
Defenders should deploy web filtering to block known C2 domains, enforce email attachment scanning for RAR/zip payloads, and apply patches for CVE-2017-0199 and CVE-2018-15982 (Flash Player vulnerability) that Qadars has exploited. SIEM rules can detect the mutex and registry key changes, and endpoint detection tools should monitor for Process Hollowing techniques used by the loader.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.