QakBot
Malware⚠️ Overview
QakBot (also known as Qbot, Pinkslipbot) is a modular banking trojan and botnet first identified in 2007, attributed to the threat group tracked as TA570 (and possibly linked to Russian-speaking actors). It evolved from a credential-stealing malware into a versatile dropper and loader used to deploy ransomware such as Conti, REvil, and ProLock. As of 2025, QakBot remains active despite law enforcement takedowns, operating as a malware-as-a-service for initial access brokers.
🔧 Technical Capabilities
QakBot propagates primarily via phishing emails with malicious attachments (e.g., Excel with malicious macros, ISO files) or URLs leading to compromised websites. Its attack vectors include web injects for credential harvesting, man-in-the-browser attacks using SSL/TLS interception, and lateral movement via Windows administrative shares and RDP. The malware uses a peer-to-peer (P2P) command-and-control (C2) infrastructure along with fallback HTTP/HTTPS C2 servers, employing domain generation algorithms (DGAs) and fast-flux DNS for resilience. Persistence is achieved through registry Run keys, scheduled tasks, and Windows service installation. Evasion techniques include code obfuscation, anti-sandboxing checks (e.g., checking for virtual machine artifacts), and use of process injection into legitimate processes like explorer.exe or svchost.exe. According to MITRE ATT&CK (S0650), QakBot also leverages PowerShell, Windows Management Instrumentation (WMI), and remote file copy for lateral movement.
📜 History & Notable Incidents
First documented by Arbor Networks in 2007, QakBot gained notoriety in 2017-2018 for targeting financial institutions in the US and Europe. In August 2023, the FBI and CISA disrupted its infrastructure under Operation Duck Hunt, seizing 34 servers and 29 domains, but the botnet re-emerged within weeks using updated C2 nodes. Notable campaigns exploited CVE-2021-26411 (Internet Explorer scripting engine memory corruption), CVE-2022-41040 (Microsoft Exchange Server privilege escalation), and CVE-2023-21716 (Microsoft Word remote code execution). High-profile victims include healthcare organizations, government agencies, and critical infrastructure entities in the US and Australia, as reported in CISA Advisory AA23-124A.
🔍 Detection Indicators
Known file hashes (MD5/SHA256) from recent campaigns include e3d0b1c9a7f8... (see CISA Malware Analysis Reports for up-to-date IOCs). Behavioral signatures include unusual outbound traffic to port 443 on non-standard IPs, registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with randomly named entries, and mutex names such as Qbot_Mutex or GlobalQBSMRT. Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 with specific DGA patterns (e.g., .com or .net domains with 12+ characters). The P2P traffic uses UDP on random high ports and TLS with self-signed certificates.
☠️ Risk & Impact
QakBot enables data exfiltration of credentials, banking details, and email account information, often leading to further compromise of corporate networks. Financial losses from ransomware deployments facilitated by QakBot have been estimated in the hundreds of millions of dollars, with the FBI reporting over 1,000 victims in 2022 alone. Affected sectors include finance, healthcare, government, manufacturing, and energy, as noted in the 2023 CISA/NCSC joint advisory.
🛡️ Mitigation
Recommended defenses include implementing multi-factor authentication, disabling macros by default, applying patches for CVEs exploited by QakBot (e.g., CVE-2023-21716 via update KB5021751), and using endpoint detection and response (EDR) tools with behavioral rules for process injection and lateral movement. The CISA-provided YARA rules and Snort signatures (e.g., SID 1000001) can detect QakBot network indicators; organizations should also block known DGA domains via DNS sinkholing and restrict outbound RDP.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.