Researchers documented Qadars as a banking Trojan focused on web-injection fraud against financial institutions, with the heaviest activity observed in the Netherlands and additional targeting in France, Canada, India, Australia, and Italy. The malware hooked Firefox and Internet Explorer to perform man-in-the-browser attacks, delivered region-specific webinjects, stored downloaded configurations encrypted in the Windows registry, and later added FTP credential theft. Campaigns were linked to pay-per-install distribution and later to the Nuclear Exploit Kit, while some operations also used Android/Perkele malware to intercept SMS transaction codes and bypass two-factor authentication during fraudulent transfers.
Later reverse engineering tied a newer sample to a likely Qadars 3.0.0.0 variant that introduced a domain generation algorithm (DGA) for command-and-control discovery, a capability not highlighted in earlier reporting on version 2. The malware was found to generate up to 200 candidate domains per cycle, resolve them with gethostbyname, and retry after a 20-second sleep if none were reachable. The DGA was described as time-dependent and deterministic, seeded by the current week so domains rotated every seven days, producing 12-character second-level domains across .com, .org, and .net to make infrastructure tracking and takedown more difficult.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
On 2016-04-12, Johannes Bader analyzed a Qadars sample with version string 3.0.0.0 and concluded that version 3 likely introduced a domain generation algorithm for command-and-control discovery. The analysis noted earlier reporting on Qadars 2.0.0.0 had not mentioned a DGA.
On 2013-12-18, ESET published an analysis describing Qadars as a banking Trojan targeting users in six countries, especially the Netherlands, and documenting capabilities including webinjects, registry-stored encrypted configs, and later FTP credential theft.
Beginning in November 2013, ESET observed Win32/Qadars being distributed through the Nuclear Exploit Kit. Earlier infection vectors from May through October 2013 had remained unclear.
ESET reported that all observed Canadian detections of Win32/Qadars occurred in the last 15 days of October 2013. This identified a distinct country-specific targeting wave within the broader campaign.
ESET said the first major infection wave of Win32/Qadars occurred in late June 2013, with Italian users mainly targeted in that wave. Later campaigns shifted primarily toward Dutch users.
ESET reported that the first signs of the Win32/Qadars banking Trojan were observed in mid-May 2013. This marked the beginning of the activity window discussed in its analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.