Elastic Security Labs documented Qbot/QakBot (also known as QBOT), a long-running modular Windows banking trojan used by multiple threat actors and ransomware affiliates. In the analyzed activity, the malware executed as a DLL through the legitimate Windows regsvr32.exe utility, used cmd.exe and curl.exe, injected into explorer.exe, copied itself into a randomly named directory beneath the user AppData path, and established persistence through Registry Run keys and scheduled tasks intended to run with SYSTEM privileges.
Qbot used anti-analysis and defense-evasion checks to identify sandbox, monitoring, and security products, and could add its persistence location to Microsoft Defender exclusions when Defender was present. It avoided execution on systems configured for Russian and several Eastern European, Central Asian, and Caucasus-region languages. The malware communicated with a distributed C2 network over HTTP or TLS using encrypted, Base64-encoded JSON, enabling operators to deliver updates, execute shell or PowerShell commands, and inject or launch additional binaries; Elastic identified 138 associated IP addresses and linked the infrastructure to hundreds of malicious files.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A 2022 QBOT V4 campaign used a multi-stage Windows DLL launched through regsvr32, process injection, Registry and filesystem persistence, SYSTEM-level scheduled-task execution, and encrypted HTTP/TLS command-and-control.
Elastic first observed QBOT in its dataset on November 28, 2020. It reported that shared infrastructure use shifted beginning that month, with QBOT DLLs comprising 97.1% of samples first seen after November 2020.
QBOT, also known as QAKBOT, began operating as a modular banking trojan and was later adopted broadly by threat actors and ransomware groups.
Dynamic and static analysis identified 138 QBOT-associated IP addresses, which Elastic linked to 339 additional malicious files. The associated samples included predominantly QBOT Win32 DLLs, EMOTET-associated executables, and malicious-spam Office attachments.
The analyzed QBOT sample injected into explorer.exe, copied itself into the user's AppData directory, created Registry Run-key persistence, and created a scheduled task to run regsvr32.exe as NT AUTHORITY\SYSTEM.
Elastic tracked REF3726 activity in which an initial cmd.exe chain tested connectivity, created C:\vyr, used curl.exe to download a disguised payload, and executed it with regsvr32.exe. Elastic Endpoint Security blocked the initial infection, after which researchers manually detonated the QBOT DLL for analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.