The U.S. Department of Justice announced a multinational operation on August 29, 2023, that disrupted QakBot, a botnet that had infected more than 700,000 computers worldwide, and seized more than $8.6 million in cryptocurrency profits. The FBI redirected botnet traffic to servers under its control and instructed infected computers to download a law-enforcement-developed QakBot uninstaller. QakBot, also known as QBot, was a banking trojan used to obtain initial access and deliver additional malware, including ransomware associated with groups such as Black Basta.
The FBI and Dutch National Police also identified compromised credentials and made resources available for victims to check their exposure. The operation disrupted a major malware-delivery platform, but its lasting impact remained uncertain. Organizations should continue monitoring for QakBot-related activity, investigate potentially affected endpoints for additional malware, and reset exposed credentials; removing QakBot does not establish that other payloads or attacker access have been eliminated.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
On August 29, 2023, the U.S. Department of Justice announced the disruption of QakBot, which had infected more than 700,000 computers worldwide, and the seizure of more than $8.6 million in cryptocurrency. The FBI redirected botnet traffic to controlled servers and instructed infected computers to download a law-enforcement-created QakBot uninstaller.
On March 15, 2023, ReliaQuest discovered a Black Basta security incident in which the attacker used QakBot for initial access. The attacker established a foothold in only 77 minutes.
The FBI and Dutch National Police identified compromised account credentials associated with QakBot and supplied them to Have I Been Pwned. Victims were directed to Have I Been Pwned and the Dutch police's Check Your Hack service to check for compromised credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.