Qadars is a Windows banking trojan associated with credential theft and online banking fraud. It has been listed among globally active PC banking trojans and has been used within financially motivated cybercrime operations, including activity linked to the broader Carbanak ecosystem. Qadars has also been observed using SSL/TLS in command-and-control communications, including self-signed certificates, indicating efforts to protect or obscure its network traffic.
Reverse engineering of a Qadars 3.x sample showed that the malware incorporated a domain generation algorithm for command-and-control discovery. The algorithm was time-dependent and deterministic, deriving weekly domain sets from the current time and rotating candidate domains on a seven-day cycle. The malware generated large batches of candidate domains, attempted resolution programmatically, and retried after a delay when none resolved. This behavior provided resilience against infrastructure takedowns and complicated static blocking.
Qadars is primarily tracked as a banking trojan rather than a generic loader or remote administration tool. Its known role in banking-focused intrusion sets places it in campaigns targeting financial institutions and victims of online banking fraud. Reporting also places it among malware families distributed through spam and phishing-driven infection chains common to banking malware operations during the mid-2010s.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
PC banking trojan listed among malware actively used to attack companies.
Banking trojan whose v3 sample uses a domain generation algorithm (DGA) to communicate with C2 servers. The DGA generates up to 200 domains per cycle, tests them with gethostbyname, sleeps 20 seconds if none resolve, and uses .com, .org, and .net TLDs with 12-character second-level domains composed of lowercase letters and digits.
Banking trojan based on ZeuS and Carbep source code, mentioned as part of the precursor group's arsenal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.