Qbot is a trojan used as an initial access malware in ransomware intrusion chains. The provided content states that email phishing is a primary delivery vector for Qbot, with dynamic phishing campaigns used to deploy the malware into victim environments. It is described as providing the initial foothold later used by Black Basta to conduct attacks, typically involving data exfiltration followed by encryption. The content also notes an affiliation between QBot and Conti, and describes an ongoing partnership between Black Basta and Qbot. High-confidence associations in the content therefore link Qbot to ransomware ecosystem operators including Black Basta and Conti. No specific technical indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan and loader used as an initial access vector in ransomware attacks, particularly in partnership with Black Basta, to facilitate data exfiltration and encryption.
QBot is a banking trojan and loader used to steal credentials and provide initial access for ransomware operations, often facilitating lateral movement and payload delivery for ransomware groups like Conti.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.