QakBot, also known as Qbot and Pinkslipbot, is a long-running cybercriminal malware operation first identified in 2007. It began as a banking trojan focused on theft of financial and browser data, then evolved into a modular access-and-delivery platform used for credential theft, email theft, reconnaissance, lateral movement, persistence, and delivery of second-stage malware. Over time, QakBot became a prominent initial access broker and botnet service in the ransomware ecosystem, providing compromised-network access to other criminal actors in exchange for a share of downstream ransom proceeds. QakBot has historically relied heavily on phishing and malspam for initial access, including malicious Excel documents, Excel 4.0 macros, VBA macros, password-protected archives, disk image files, ISO files, LNK files, JavaScript and HTA downloaders, and later malicious OneNote documents with embedded payload launchers. Operators have repeatedly abused hijacked email threads stolen from prior victims to increase delivery credibility. Campaigns have also shifted delivery formats in response to defensive changes such as Microsoft macro restrictions and Mark-of-the-Web protections. The malware is modular and highly evasive. Documented capabilities include theft of browser credentials, cookies, keystrokes, and email data; collection of victim system information; persistence via scheduled tasks and other mechanisms; process injection and process hollowing into legitimate Windows processes; dynamic API resolution and encrypted command-and-control communications; and deployment of plug-ins for hidden VNC access, UPnP proxying, lateral movement, Cobalt Strike, and remote administration tooling. QakBot operators have used hidden-desktop VNC functionality, including the Dark Cat variant, to conduct hands-on-keyboard activity such as browser inspection, Outlook access, command execution, reconnaissance, and staging of follow-on tooling. QakBot is closely associated with post-compromise ransomware activity. In multiple intrusion chains, QakBot infections were followed by Cobalt Strike and rapid escalation to domain-wide compromise, lateral movement, credential abuse, and ransomware deployment. Reported downstream ransomware relationships include DoppelPaymer, MegaCortex, PwndLocker, ProLock, Egregor, Sodinokibi/REvil, Black Basta, and later affiliate-linked delivery of Ransom Knight alongside Remcos after the 2023 infrastructure disruption. U.S. law-enforcement filings state that QakBot administrators facilitated attacks by ransomware actors and received portions of ransom payments through virtual currency, reinforcing its role as a criminal access brokerage and malware distribution conspiracy rather than a purely standalone banking trojan. The operation has shown sustained adaptability. It adopted LNK-based delivery after macro blocking changes, used techniques to evade Mark-of-the-Web protections, increasingly leveraged crypters associated with ITG23-linked developers from 2022 onward, and remained active after the August 2023 international takedown of core infrastructure. Law-enforcement actions in 2023 disrupted botnet infrastructure and later led to 2025 forfeiture and indictment actions tied to ransomware proceeds, but reporting indicates the operators or affiliates continued phishing and malware-delivery activity afterward. QakBot is a financially motivated cybercriminal operation with global victimization. Reported targeting has included organizations in the United States, Japan, Germany, and other countries, with notable impact across telecommunications, technology, education, and other critical industries. Its enduring significance lies in its role as a mature malware platform and access broker that bridges commodity phishing operations and high-impact human-operated ransomware intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used HTML smuggling files to deliver initial access payloads during 2022 and 2023.
A long-running cybercrime operation that evolved from a banking trojan into an initial access broker. In this content it is actively distributed post-takedown via MSI, LNK, BAT, and ZIP-based delivery, using DLL sideloading, encrypted configuration data, and a tiered proxy/C2 architecture, with campaigns targeting military and government entities.
Associated in the content with use of DLL side-loading via calc.exe loading a malicious WindowsCodecs.dll from a non-standard location.
Associated with process injection activity using remote thread execution into legitimate Windows processes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.