Researchers across multiple security firms documented how QakBot (also known as Qbot) has evolved from a banking trojan into a stealthier modular malware platform that steals credentials, injects into processes such as explorer.exe, and can act as a loader for follow-on ransomware. Reports describe delivery through phishing documents, exploit droppers, and open shares, with campaigns targeting financial institutions in the United States and additional banks in Canada and the Netherlands. Analysts also observed persistent development activity, frequent packing changes, browser-injection capabilities, FTP exfiltration, DGA-based command-and-control behavior, and increasingly organized build practices designed to frustrate signature-based detection.
More recent samples show QakBot reducing on-disk artifacts by storing configuration in the Windows Registry, writing Run-key persistence only around shutdown or reboot, and deleting dropped components after execution on the next boot. Researchers also detailed anti-analysis checks for Windows Defender, Sandboxie, analyst tooling, VMware artifacts, RAM heuristics, and CPUID-based virtualization detection, alongside encrypted resources and string tables that hide campaign IDs and C2 infrastructure. To counter that obfuscation, defenders published tooling and workflows to recover QakBot configurations, strings, embedded payloads, and RC4- or AES-protected data at scale, including extractors for PE resources, memory-carving approaches for injected payloads, and Binary Ninja automation that recovered campaign data and live C2 endpoints from 64-bit samples.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Invoke RE published a Binary Ninja-based workflow for unpacking 64-bit QakBot, recovering API hash tables, decrypting string tables, and extracting campaign and C2 configuration. One analyzed sample yielded campaign ID tchk06, timestamp 1702463600, and C2 endpoints 45.138.74.191:443 and 65.108.218.24:443.
Rapid7 described a method for extracting recent QakBot configuration data and released the Windows.Carving.Qakbot Velociraptor artifact to automate detection of injected payloads and parsing of strings and configuration. The post also documented recent samples' two-stage RC4 decoding and configuration storage in PE resources.
Lab52 published analysis of a QakBot sample showing checks for Windows Defender artifacts, security and analysis processes, Sandboxie-related modules, analyst-style filenames, VMware backdoor I/O, RAM heuristics, and CPUID-based virtualization detection. The report noted the malware can terminate execution when such conditions are detected.
Elastic Security Labs published qbot-config-extractor, a Python-based tool and CLI for extracting configuration data from QBOT malware samples. The release included example output recovering embedded strings, persistence commands, and C2 endpoints from a sample.
Elastic Security Labs published an analysis of a QBOT sample's execution chain, persistence, privilege escalation, defense evasion, and network behavior, including language-based execution checks, Defender exclusion abuse, and a scheduled task running as SYSTEM. The researchers also correlated 138 IPs tied to the sample with 338 additional malicious samples and released YARA rules plus an open-source QBOT configuration extractor to support detection and analysis.
Splunk documented that QakBot campaigns changed from June to October 2022 after Office macros were disabled by default, adopting HTML smuggling, password-protected ZIP archives, and ISO containers with LNK files and scripts to evade Mark-of-the-Web protections. The analysis also described regsvr32-based DLL execution, process injection, and related evasion techniques used in these campaigns.
A 0ffset blog post published reverse-engineering details on QakBot's browser hooking module, including automated recovery of decrypted strings, hashed API resolution, and internal hook structures using IDA Python scripts. The analysis also noted that Chrome hooking is more complex because QakBot must parse internal Chrome libraries rather than rely on normal exported APIs.
A later Lab52 analysis states that CISA identified QakBot as one of the most active malware variants in 2021, reflecting a notable level of operational activity that year.
Hornetsecurity documented an updated QakBot variant that moved configuration storage to the registry and delayed writing its Run key and dropped DLL until shutdown or reboot, deleting them after the next boot. The report also described runtime-only string decoding, anti-analysis checks, and use of a valid code-signing certificate tied to Aqua Direct s.r.o.
Trend Micro reported that since late 2020, QakBot operators have used malicious Microsoft Excel documents with heavily obfuscated Excel 4.0 macros for initial access. The report says this delivery method likely benefited from the lack of Excel 4.0 macro support in AMSI before March 2021.
F5 Labs reported a renewed Qbot campaign using updated packing and anti-VM techniques while continuing credential theft and browser hijacking. The analyzed target list focused mainly on about 36 U.S. financial institutions, with additional banks in Canada and the Netherlands.
Check Point reported that a prominent Qbot campaign ran from March through the end of June 2020, targeting organizations in the United States and Europe via hijacked email threads and ZIP-delivered VBS downloaders. The analysis documented newly observed capabilities including an email collector used to harvest Outlook threads for future malspam, hVNC support, and a bot-proxy mechanism.
Vkremez published an in-depth reverse-engineering analysis of QakBot. The post introduced additional technical details about the malware's internals and behavior not already reflected in the existing timeline.
Cisco Talos published research describing a resurgence in Qbot activity and analyzed 618 packed samples that reduced to 73 unique samples. The report detailed Qbot's packing, persistence, FTP exfiltration, DGA-based C2 behavior, and recently added webinject capability for banking-session manipulation.
McAfee reported that starting in April 2016, QakBot/Pinkslipbot began turning infected machines into externally reachable HTTPS proxy nodes by abusing UPnP to open router ports. The change let compromised hosts mask the real command-and-control infrastructure and followed a shift away from relying primarily on DGA-based control.
Multiple references state that Qbot, also known as Qakbot, has been active since 2008, marking the earliest anchored point in the malware family's history.
The Zscaler analysis states that Qakbot version 2.0.1 introduced a time-based domain generation algorithm as a backup command-and-control channel, capable of generating up to 5,000 domains for a given date interval. The report also notes some versions generated fake domains in analysis environments to mislead researchers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceinvokere.com
Open sourcerapid7.com
Open sourcelab52.io
Open sourcemcafee.com
Open sourceblog.talosintelligence.com
Open sourcedocuments.trendmicro.com
Open sourcevkremez.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.