QakBot, also known as QBot, Pinkslipbot, and Quackbot, is a Windows malware family that emerged around 2008 as a banking trojan and evolved into a malware loader and initial-access platform for financially motivated cybercriminals. Its infections have supported ransomware operations involving Black Basta, Conti, and REvil, including deployment of Cobalt Strike and other follow-on payloads. QakBot enables ransomware delivery rather than functioning as ransomware itself.
QakBot spreads through phishing emails containing malicious links or attachments. Observed delivery formats include Excel documents, OneNote attachments, and Windows shortcuts. Its capabilities include credential theft, persistence, remote-system discovery, process injection, and worm-like lateral movement through SMB exploitation. It can identify networked systems using Windows network-enumeration commands and communicate with command-and-control infrastructure over TCP. It also contains functionality to export victims' private keys from the Windows Certificate Store when those keys are marked as exportable.
Defense-evasion techniques include injecting code into legitimate Windows processes, disguising payloads as PNG images, and abusing valid code-signing certificates to make malicious components appear trustworthy. QakBot has also been used in conjunction with DLL hijacking. Its role as an access and payload-delivery service made its botnet an important component of the ransomware ecosystem before a major FBI-led disruption in 2023. The Windows QakBot family is distinct from the unrelated Gafgyt/BASHLITE IoT malware sometimes called Qbot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit CVE-2020-1472 (also known as “ZeroLogon”) to gain Domain Administrative privileges. This tool and its intrusion attempts have been reportedly related to Hancitor and Qbot.
members of the VirusTotal community have linked it to exploitation of CVE-2022-30190, a Microsoft Support Diagnostic Tool (MSDT) vulnerability also known as Follina. Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT, and Qbot, which has previously delivered ransomware as a later-stage payload. | Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT (remote access trojan), and Qbot, which has previously delivered ransomware as a later-stage payload.
First, unpatched Exchange servers are exploited using ProxyShell... We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October. | We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
After approximately 2 minutes, QBot attempted to exploit the PrintNightmare vulnerability by executing the Invoke-Nightmare PowerShell command to create an administrative user with the username admin1 and password Password. | QBot, also known as Qakbot, is a malware that has been present on the threat landscape since 2007. QBot originally featured information stealing and trojan functionalities, however, the malicious actors that develop QBot have extended the malware with malware loading capabilities.
Together they form a re-packaged exploit for Silverlight based on CVE-2016-0034 (MS16-006) – a Silverlight Memory Corruption vulnerability. The exploit has previously been used by several exploit kits including RIG and Angler to deliver multiple crimeware tools. | The DLL (MD5 hash: 7b4a8be258ecb191c4c519d7c486ed8a) is identical to the one reported in a malware traffic analysis blog post from March 2016 where it was used to deliver Qbot.
In early October, the same “TR” distributor was reportedly conducting brute-force attacks on Internet Message Access Protocol (IMAP) services, and there is also speculation from security researchers that “TR” uses ProxyLogon to acquire credentials for the attacks. | QAKBOT is a prevalent information-stealing malware that was first discovered in 2007. In recent years, its detection has become a precursor to many critical and widespread ransomware attacks.
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
This led us to suspect that ProxyLogon and ProxyShell vulnerabilities are being exploited. These vulnerabilities allow Quakbot threat actors to bypass email security policies and propagate Quakbot infections. ProxyLogon – CVE-2021-26855, CVE-2021-27065
The 3rd method - using malformed digital signatures (CVE-2022-44698) - patched on December 13 and is actively exploited in the wild. Because of the malformed digital signature, the loader bypasses the Mark of the Web (MoTW) flag, and the execution proceeds without a Windows warning pop-up message. | At the beginning of November 2022, EclecticIQ analysts examined a recent campaign that delivers QakBot (also called Qbot) to victim devices via phishing emails, executes by abusing multiple Living Off the Land Binaries (LOLBAS) and evades the Mark of the Web (MoTW) flag to increase the infection rate.
CVE-2024-30051 (CVSS skóre 7,8) Zero-day zraniteľnosť v knižnici Windows DWM Core Library by lokálny autentifikovaný útočník s oprávneniami štandardného používateľa mohol prostredníctvom zaslania špeciálne vytvorenej požiadavky zneužiť na eskaláciu privilégií (úroveň SYSTEM) a získať úplnú kontrolu nad systémom. Spoločnosť KASPERSKY informovala o phishingových kampaniach, ktoré túto zraniteľnosť aktívne zneužívajú na šírenie malvéru QAKBOT. | Spoločnosť KASPERSKY informovala o phishingových kampaniach, ktoré túto zraniteľnosť aktívne zneužívajú na šírenie malvéru QAKBOT.
"The threat actor gained initial access to the organization via Qakbot infection..." | The threat actor gained initial access to the organization via Qakbot infection, followed by the exploitation of a Windows CLFS vulnerability (CVE-2023-28252) to elevate their privileges on affected devices.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
Threat Details and IOCs Malware: ... Qbot ...
34 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
QakBot, also called QBot, began as a banking trojan around 2008 and became one of the most widely used initial-access tools for ransomware.
On August 29, 2023, the U.S. Department of Justice announced that a multinational operation successfully disrupted the QakBot botnet, which infected over 700,000 computers worldwide.
On August 29, 2023, the U.S. Department of Justice announced that a multinational operation successfully disrupted the QakBot botnet, which infected over 700,000 computers worldwide.
On August 29, 2023, the U.S. Department of Justice announced that a multinational operation successfully disrupted the QakBot botnet, which infected over 700,000 computers worldwide.
On August 29, 2023, the U.S. Department of Justice announced that a multinational operation successfully disrupted the QakBot botnet, which infected over 700,000 computers worldwide.
On August 29, 2023, the U.S. Department of Justice announced that a multinational operation successfully disrupted the QakBot botnet, which infected over 700,000 computers worldwide.
46 distinct techniques documented for this family, organized by ATT&CK tactic.
Process injection was used by both the initial QBot payload (into WERMGR.EXE) and the subsequent deployment of Cobalt Strike (into WERFAULT.EXE).
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
3,031 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Provides initial access through phishing and changing delivery formats, including OneNote attachments, HTML smuggling, and ZIP archives. Commonly deploys Cobalt Strike and facilitates ransomware delivery. The article describes disruptions in 2023 and 2025.
Named as a source of capabilities inherited by historical Rebirth/Vulcan malware. The content does not specify those capabilities or establish equivalence with other similarly named malware.
Malware associated here with injecting malicious code into legitimate browser processes via wermgr.exe in order to steal information; the detection notes this could enable arbitrary code execution, privilege escalation, and data exfiltration on the compromised host.
Mentioned only as a comparison point for BumbleBee C2 tracking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.