QakBot, also known as Qbot, QuakBot, and Pinkslipbot, is a long-running modular Windows crimeware malware family and botnet that originated as a banking trojan and evolved into a multifunctional loader, backdoor, and credential theft platform. It has been active since at least 2007 and is widely associated with financially motivated cybercrime operations targeting corporate environments. QakBot is commonly delivered through phishing campaigns and has repeatedly adapted its initial-access tradecraft to changing defensive controls. Observed delivery methods include malicious Office documents with macros, password-protected ZIP archives containing ISO or IMG disk images, malicious JavaScript, and MSI installer packages. Campaigns have also leveraged exploitation techniques such as abuse of Mark-of-the-Web bypasses and Follina to execute payloads without relying on traditional macro enablement. Once executed, QakBot commonly loads as a DLL and injects into legitimate Windows processes for defense evasion. Reported post-compromise behavior includes rapid reconnaissance, privilege escalation, theft of browser data and Outlook email, credential dumping from LSASS, brute-force activity against Active Directory administrative accounts, and lateral movement to adjacent systems. It has also been observed creating scheduled tasks, modifying Microsoft Defender exclusions, and using legitimate remote monitoring and management tools such as Atera and Splashtop as alternative persistent-access channels. QakBot functions both as an information stealer and as an access broker for follow-on payloads. It has been observed delivering Cobalt Strike and Brute Ratel, and intrusions involving QakBot have been linked to subsequent ransomware deployment by groups including REvil, Egregor, ProLock, MegaCortex, PwndLocker, and later Black Basta. QakBot operators have also been associated with replay-chain phishing through theft of victim emails and with broader enterprise compromise shortly after initial infection. The malware is part of the broader crimeware ecosystem and has operational overlap with other financially motivated malware operations, including use by or association with actors tied to Emotet, IcedID, TrickBot, and SystemBC-related services. Its enduring relevance stems from its modularity, rapid post-exploitation workflow, and role as a high-value initial-access and malware-delivery platform in ransomware intrusion chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed delivering the Brute Ratel post-exploitation framework in 2022.
Affiliated threat actors use RMM tools such as Atera and Splashtop, alongside Cobalt Strike, to maintain persistent access in compromised environments.
Mentioned only as background association for an IP address tied to related activity; not the subject of the incident.
Conducting phishing campaigns to deliver QBot via password-protected archives and mounted disk images, abusing a Windows Mark of the Web zero-day bypass to execute malicious JS and load DLL payloads without security warnings. The malware is then used as a loader for follow-on intrusion activity and additional payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.