QakBot (also referred to in the provided content as Quakbot) is a Windows malware family observed both as a standalone payload and as a secondary tool delivered by other malware. In the supplied reporting, a March 2026 investigation linked a Quakbot LNK sample to infrastructure used by the actor tracked as "evilgrou-tech," alongside QuasarRAT and DarkMe RAT. That operation used GitHub-hosted encrypted payloads, PowerShell loaders, regsvr32 COM scriptlets, mshta execution, fileless Assembly.Load execution, and persistence via Run keys, Startup links, and HTA files. The same reporting assessed the actor with moderate-to-high confidence as related to the WaterHydra/DarkCasino lineage and stated the campaign targeted forex traders in Italy and cryptocurrency users associated with "Pumpfun." Separate March 2026 phishing activity targeting Ukrainian entities was also linked through MalwareBazaar pivots to a broader campaign in which related samples were tagged with UKR, UAC-0252, Quakbot, and RClone-Stealer-Mega, although attribution there was low confidence and the final payload could not be recovered. The content also states that in early 2018 Emotet used its loader functionality to spread Quakbot and ransomware variants, indicating Quakbot has been used as a follow-on payload in broader malware delivery operations. High-confidence indicators directly mentioned in the content include association of one Quakbot LNK sample with the same C2 infrastructure used in the evilgrou-tech cluster and campaign tagging in MalwareBazaar references; no standalone Quakbot-specific configuration, mutex, or file path was provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MalwareBazaar pivot analysis ties this sample to a broader campaign cluster exploiting CVE-2025-8088 (WinRAR)... Second, CVE-2025-8088 (a WinRAR vulnerability) appears in three related samples from March 3-10. The password-protected RAR in our sample may be designed to exploit this same vulnerability during extraction. Without the password, we cannot confirm this -- but the pattern is suggestive.
Miscreants have been seen exploiting the Follina flaw, tracked as CVE-2022-30190, in the Windows Support Diagnostic Tool to deliver Qbot... Follina is a remote code execution (RCE) vulnerability in the Microsoft Support Diagnostic Tool; this can be exploited by getting an application, such as Word, to call out to the tool from a specially crafted document when opened.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The March 3 sample tagged UAC-0252 provides a tentative attribution anchor... 2026-03-03 27d7a398... ZIP UKR, Quakbot, RClone-Stealer-Mega Algeria-Ukraine cooperation
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Then, we observe that the memory section is filled with obfuscated data... additional string fractures such as: “This program cannot run in DOS mode” and the word “PE”, will be revealed.
In malware, we often see threat actors that tend to obfuscate or encrypt their code in order to slow down the analysis of security researchers... many authors tend to use open-source packers but also craft their own custom packers.
This technique is called Stack-Strings and will appear several times during the Qbot unpacking process.
These instructions assign the HEX value “47 65 74 50 72 6f 63 41 64 64 72 65 73 73” to the ECX register... This technique is called Stack-Strings... Then, the GetProcAddress string being used by another function.
At first glance, it seems this loop has characteristics we expect from traditional decryption\encryption routines, such as shr (shift right), xor , and rol (rotate left) opcodes... The loop changes the first bytes of the obfuscated content to “M8Z”, which starts to resemble the classic “MZ” string.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a malware family found in a related campaign sample within the broader Ukraine-targeting cluster; the analyzed BES PDF lure itself did not reveal its final payload.
A tertiary malware tool observed as a single LNK sample associated with the same infrastructure as the main operation.
Quakbot is mentioned as a malware family spread by Emotet via its loader function in early 2018.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.