QtBot is a Windows malware downloader used as an intermediate stage in Necurs-delivered malspam campaigns. It became notable for replacing earlier VBA-based geotargeting logic in malicious Microsoft Office document infections and for selectively delivering different final payloads based on victim geolocation, including TrickBot and Locky. Campaign lures commonly used financial and document-delivery themes such as invoices, billing notices, receipts, fax notifications, and scanned-file messages.
In observed infections, malicious Office documents abused Dynamic Data Exchange to launch command execution and PowerShell, which retrieved QtBot from attacker-controlled infrastructure. Once executed, QtBot performed connectivity checks, established command-and-control communications over HTTP POST, and used RC4-encrypted data for strings and network traffic. It acted primarily as a downloader and staging component, retrieving and launching a second-stage payload chosen according to GeoIP-based targeting.
QtBot incorporated a comparatively robust anti-analysis and defense-evasion suite. It scanned running processes for common debugging, reverse-engineering, sandboxing, and monitoring tools and terminated if such tools were present. It also checked keyboard layouts associated with former USSR countries and avoided execution on those systems. The malware used process injection as part of its execution chain, decrypting code in memory and injecting into legitimate Windows processes including msiexec.exe and a spawned svchost.exe instance.
For host tracking and persistence, QtBot created a randomly generated mutex, stored configuration-related values under a QtProject-themed registry location, and maintained persistence through artifacts in a randomly named temporary folder under the user profile. Reported tradecraft overlaps with Andromeda include anti-analysis checks, keyboard-layout filtering, infection reporting patterns, and injection into msiexec.exe, although QtBot has been treated as a distinct malware family.
QtBot primarily targeted Windows enterprise and consumer endpoints reached through large-scale spam distribution. Its role in delivering both banking malware and ransomware made it an important modular component in financially motivated email-borne intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These documents load an intermediate downloader which we have tagged in AutoFocus as “QtBot”. QtBot replaces the previously discussed VBA and features a robust anti-analysis suite to protect itself. This new downloader is responsible for loading the final payload, either Locky or Trickbot, again based on GeoIP.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
For persistence, a temp file is generated with a randomly generated name and stored in %APPDATA%\Local\Temp\ in a randomly named folder. This randomly generated value is used for the folder name and is stored in the registry key “HKCU\Software\QtProject”
そして、サスペンド状態で起動させた自身の子プロセス「rekakva32.exe」(第2世代)に対しプロセスハロウイングを行います。
For persistence, a temp file is generated with a randomly generated name and stored in %APPDATA%\Local\Temp\ in a randomly named folder. This randomly generated value is used for the folder name and is stored in the registry key “HKCU\Software\QtProject”
システム起動時に実行されるよう以下のレジストリを作成します。・レジストリキー: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
そして、サスペンド状態で起動させた自身の子プロセス「rekakva32.exe」(第2世代)に対しプロセスハロウイングを行います。
「svchost.exe」は動作を開始すると、WinHttpConnect関数を使用し、以下のドメインに接続可能かどうかを確かめます。これは正規のWindows Updateに関わるドメインであり、感染環境がインターネットに接続されているかどうかのチェックに利用します。
When QtBot initially executes, a new thread is created which is responsible for process scanning. This process scanning is used to identify analysis tools and, if any are found, terminate the malware’s further execution.
「svchost.exe」は動作を開始すると、WinHttpConnect関数を使用し、以下のドメインに接続可能かどうかを確かめます。これは正規のWindows Updateに関わるドメインであり、感染環境がインターネットに接続されているかどうかのチェックに利用します。
This new downloader is responsible for loading the final payload, either Locky or Trickbot, again based on GeoIP.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Next: Everybody Gets One: QtBot Used to Distribute Trickbot and Locky
Next: Everybody Gets One: QtBot Used to Distribute Trickbot and Locky
Intermediate downloader/loader delivered via malicious DDE Office documents in malspam. It performs anti-analysis checks, avoids former USSR keyboard layouts, injects into msiexec.exe and svchost.exe, persists via registry and temp files, communicates with C2 using RC4-encrypted HTTP POSTs, and geo-targets delivery of either Trickbot or Locky.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.