Zscaler ThreatLabz reported that the Ares banking trojan was updated with a fallback domain generation algorithm (DGA) that closely mirrors the older DGA used by Qakbot. Reverse engineering indicates the logic was likely reimplemented from public knowledge rather than copied directly from Qakbot’s codebase. The added DGA gives Ares a way to recover command-and-control communications if its primary infrastructure is disrupted, while the malware also retains hardcoded infrastructure including tomolina[.]top/panel/connect.php.
The Qakbot DGA that Ares appears to emulate is designed to generate large batches of pseudo-random domains using a date-based seed and CRC-32-derived values, with support for multiple top-level domains including .com, .net, .org, .info, and .biz. Zscaler said the Ares update also modified its API hashing routine using logic derived from the Kronos/Osiris lineage to hinder static detection, and linked current activity to campaigns targeting financial institutions in Mexico, including a hardcoded web inject configuration aimed at BBVA Mexico.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz reported that none of the example Ares DGA domains generated for August 29, 2022 resolved at the time of publication.
ThreatLabz said newly analyzed Ares samples carrying the updated functionality were compiled on August 15, 2022.
In August 2022, Ares was updated to add a fallback domain generation algorithm for command-and-control when its primary hardcoded infrastructure is unreachable. ThreatLabz assessed the implementation closely mirrors Qakbot's older DGA but was likely reimplemented rather than copied directly from Qakbot code.
Zscaler ThreatLabz reported that the threat actors using the Ares banking trojan were inactive from approximately March 2022 to June 2022.
The reverse-engineering post analyzed a Qakbot.T sample dated December 23, 2015, which unpacked to an executable that decrypted and loaded a Qakbot DLL. Microsoft detected all three analyzed stages as Qakbot.T.
The Qakbot banking trojan had relied on a domain generation algorithm for command-and-control communication since at least September 2013, according to the reverse-engineering analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 607 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.