Researchers analyzing QakBot v5.0 reported that the long-running malware family has added support for 64-bit Windows while preserving its role as a modular loader and information stealer. The examined sample, a 64-bit DLL seen in the wild in early February 2024, uses layered anti-analysis techniques including sandbox, emulator, process, and virtual machine checks, and relies on CRC32-based API hashing with an added XOR layer to obscure functionality. Analysts also found updated string handling in which an encrypted xor_key_blob is first decrypted before being used to recover embedded strings tied to execution paths, persistence, WMI queries, virtualization detection, security-product checks, and command execution.
The malware stores configuration data in the .data section and protects it with AES-based encryption, while its command-and-control traffic is sent over HTTP using AES-encrypted, Base64-encoded payloads. Recovered configuration details included the QakBot ID tchk08, flag 40=1, and a timestamp of 2024-01-31 21:22:34; analysts also extracted C2 endpoints at 31.210.173.10:443, 185.156.172.62:443, and 185.113.8.123:443. Beyond communications, QakBot v5.0 performs extensive host reconnaissance through WMI, Windows APIs, and shell commands, supports process hollowing, and maintains persistence through registry entries or scheduled tasks, underscoring its continued evolution as a stealthy post-compromise platform.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The analyzed QakBot v5.0 sample was first seen in the wild on 2024-02-07 10:12:50 UTC. The sample is identified as a 64-bit Windows DLL associated with the updated QakBot codebase.
Decoded configuration data from the new 64-bit QakBot sample contained ID "tchk08," field "40=1," and a timestamp of 21:22:34 on 2024-01-31. This reflects a configuration/campaign timestamp recovered during analysis.
The QakBot v5 sample analyzed in the research was created as a 64-bit Windows DLL. One source gives the sample creation timestamp as 2024-01-29 13:43:37 UTC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.