QakBot, also known as Qbot, Pinkslipbot, and QuackBot, is a Windows banking Trojan that evolved into an information-stealing malware family and loader for follow-on payloads. It collects host and security-product information, can steal credentials and email data, and has been used for reconnaissance and delivery of additional malware. QakBot supports persistence through mechanisms including scheduled tasks and BITS jobs, and can use process injection to evade detection. It has frequently served as an access and payload-delivery mechanism in ransomware intrusions, including incidents involving Cobalt Strike, Brute Ratel, and ransomware families such as Egregor, ProLock, Black Basta, and Conti. QakBot has been distributed through phishing email campaigns using social-engineering lures, including malicious Microsoft OneNote documents, password-protected archives, disk images, and script-based execution chains. TA577 has used OneNote-based phishing to distribute QakBot. The malware primarily targets Windows environments across multiple industries and geographies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
members of the VirusTotal community have linked it to exploitation of CVE-2022-30190, a Microsoft Support Diagnostic Tool (MSDT) vulnerability also known as Follina. Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT, and Qbot, which has previously delivered ransomware as a later-stage payload. | Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT (remote access trojan), and Qbot, which has previously delivered ransomware as a later-stage payload.
First, unpatched Exchange servers are exploited using ProxyShell... We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October. | We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
After approximately 2 minutes, QBot attempted to exploit the PrintNightmare vulnerability by executing the Invoke-Nightmare PowerShell command to create an administrative user with the username admin1 and password Password. | QBot, also known as Qakbot, is a malware that has been present on the threat landscape since 2007. QBot originally featured information stealing and trojan functionalities, however, the malicious actors that develop QBot have extended the malware with malware loading capabilities.
Thirty minutes after gaining initial access, the threat actors ran an executable file on the beachhead to exploit CVE-2020-1472, Zerologon... Successful exploitation of the Zerologon allowed the threat actors to obtain domain admin privileges. | In this intrusion (from November 2021), a threat actor gained its initial foothold in the environment through the use of Qbot malware. Soon after execution of the Qbot payload, the malware established C2 connectivity and created persistence on the beachhead.
Together they form a re-packaged exploit for Silverlight based on CVE-2016-0034 (MS16-006) – a Silverlight Memory Corruption vulnerability. The exploit has previously been used by several exploit kits including RIG and Angler to deliver multiple crimeware tools. | The DLL (MD5 hash: 7b4a8be258ecb191c4c519d7c486ed8a) is identical to the one reported in a malware traffic analysis blog post from March 2016 where it was used to deliver Qbot.
In early October, the same “TR” distributor was reportedly conducting brute-force attacks on Internet Message Access Protocol (IMAP) services, and there is also speculation from security researchers that “TR” uses ProxyLogon to acquire credentials for the attacks. | QAKBOT is a prevalent information-stealing malware that was first discovered in 2007. In recent years, its detection has become a precursor to many critical and widespread ransomware attacks.
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
This led us to suspect that ProxyLogon and ProxyShell vulnerabilities are being exploited. These vulnerabilities allow Quakbot threat actors to bypass email security policies and propagate Quakbot infections. ProxyLogon – CVE-2021-26855, CVE-2021-27065
The 3rd method - using malformed digital signatures (CVE-2022-44698) - patched on December 13 and is actively exploited in the wild. Because of the malformed digital signature, the loader bypasses the Mark of the Web (MoTW) flag, and the execution proceeds without a Windows warning pop-up message. | At the beginning of November 2022, EclecticIQ analysts examined a recent campaign that delivers QakBot (also called Qbot) to victim devices via phishing emails, executes by abusing multiple Living Off the Land Binaries (LOLBAS) and evades the Mark of the Web (MoTW) flag to increase the infection rate.
CVE-2024-30051 (CVSS skóre 7,8) Zero-day zraniteľnosť v knižnici Windows DWM Core Library by lokálny autentifikovaný útočník s oprávneniami štandardného používateľa mohol prostredníctvom zaslania špeciálne vytvorenej požiadavky zneužiť na eskaláciu privilégií (úroveň SYSTEM) a získať úplnú kontrolu nad systémom. Spoločnosť KASPERSKY informovala o phishingových kampaniach, ktoré túto zraniteľnosť aktívne zneužívajú na šírenie malvéru QAKBOT. | Spoločnosť KASPERSKY informovala o phishingových kampaniach, ktoré túto zraniteľnosť aktívne zneužívajú na šírenie malvéru QAKBOT.
"The threat actor gained initial access to the organization via Qakbot infection..." | The threat actor gained initial access to the organization via Qakbot infection, followed by the exploitation of a Windows CLFS vulnerability (CVE-2023-28252) to elevate their privileges on affected devices.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
Threat Details and IOCs Malware: ... Qbot ...
29 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA577 returned from a month-long hiatus in activity and began using OneNote to deliver Qbot at the end of January 2023.
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
"1580103814": "APT27/Qbot/IcedID/DarkSide/Conti/Hancitor/WizardSpider - Stats uniques -> ips/hostnames: 85 publickeys: 39"
the financially motivated GOLD LAGOON threat group leverages the Qakbot botnet to deploy Cobalt Strike... The attachment downloaded and installed Qakbot. Qakbot profiled the infected host, sent the profiled data to its C2 servers, and then downloaded and executed Cobalt Strike Beacon.
In this latest campaign, the Black Basta ransomware gang is using QakBot malware to create an initial point of entry and move laterally within an organization’s network. QakBot, also known as QBot or Pinkslipbot, is a banking trojan primarily used to steal victims’ financial data, including browser information, keystrokes, and credentials.
Compromised servers are then used to spread phishing emails delivering Datoploader (aka Squirrelwaffle) and the QBot trojan.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial access techniques include malvertising, callback phishing ... and forum or blog comments containing malicious links. These lead to downloads of malware, including BATLOADER and Qakbot, which in turn deliver secondary payloads that eventually lead to ransomware deployment.
In recently observed attacks, threat actors sent emails containing .Zip archives to potential victims. Email lures commonly relate to employee compensation.
In observed attacks, threat actors employ the use of mounting disk image formats such as ISO/IMG based-attachments containing .LNK/.VBS payloads.
"schtasks.exe /Create /RU \"NT AUTHORITY\SYSTEM\" /SC ONSTART /TN %u /TR \"%s\" /NP /F"
the .LNK file executes a command to download and execute a Qakbot payload.
The payload within OneNote attachment is a Windows Command Script (.cmd) file that contains the PowerShell command to download the Qakbot payload.
The payload within OneNote attachment is a Windows Command Script (.cmd) file that contains the PowerShell command to download the Qakbot payload.
Every minute, the native Windows Script Host utility, wscript.exe, will execute the malicious VBScript file, AppPool.vbs, which resides in the ProgramData subdirectory.
Threat groups like APT40 and malware families such as the Qbot banking trojan have used BITS to transfer malicious files and set up persistence.
Base64 encodes data on the endpoint’s operating system version and antivirus software, which it passes back to C2 in the beacon URI.
In observed attacks, threat actors employ HTML smuggling ... and password protected ZIP archives to bypass email-based security detections.
This variant utilizes a .vbs dropper by masquerading as a .doc file, as Windows still hides the original filename extension by default.
Observed Reconnaissance Commands: ... ipconfig /all ... route print
The extracted strings include the command "netstat -nao."
3,015 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware associated here with injecting malicious code into legitimate browser processes via wermgr.exe in order to steal information; the detection notes this could enable arbitrary code execution, privilege escalation, and data exfiltration on the compromised host.
Mentioned only as a comparison point for BumbleBee C2 tracking.
Initial access/backdoor malware used after spearphishing to establish control, persist via a Windows Registry Run key, and support lateral movement ahead of Royal ransomware deployment.
Botnet referenced in connection with Cobalt Strike watermark analysis on BitLaunch infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.