Threat actors used QakBot (also tracked as QBot/QuackBot) as an initial access and post-compromise platform in corporate intrusions, delivering the malware through phishing campaigns that evolved from malicious Office documents to password-protected ZIP archives, MSI installers, OneNote files, LNK/XLL payloads, and script-based chains. Across these campaigns, QakBot established persistence, injected into legitimate processes, conducted host and domain reconnaissance, stole credentials and other data, and communicated with command-and-control servers over encrypted HTTP/HTTPS channels before staging additional payloads.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Morphisec Labs reported a large QakBot phishing campaign that began earlier in January 2025 using ZIP archives containing malicious Word documents with AutoOpen and AutoClose macros. The campaign used two notable evasion techniques: placing the document in a ZIP file to bypass content disarm and reconstruction controls, and launching VBS execution through explorer.exe to evade child-parent process detection before downloading the QakBot payload from multiple URLs.
In late August 2023, the FBI and international partners seized Qakbot infrastructure and cryptocurrency assets. Talos assessed the operation significantly damaged Qakbot operations, particularly command-and-control infrastructure.
Threat actors linked by Cisco Talos to Qakbot affiliates began a phishing campaign in early August 2023 distributing ZIP archives containing LNK and XLL files. The campaign delivered a Ransom Knight ransomware variant and the Remcos backdoor, with some lures themed around invoices and bank transfers, including Italian-language filenames.
The actor behind the Cyclops ransomware service announced Ransom Knight, described as an updated variant rewritten from scratch. Later reporting assessed that Qakbot-affiliated actors likely used the service as customers rather than operators.
Microsoft started rolling out the VBA macro autoblock feature to Office for Windows users in early April 2022, beginning with Office Version 2203 in the Current Channel (Preview). This rollout was cited as context for Qbot's shift away from macro-heavy delivery chains.
DFIR Report published an incident analysis describing a November 2021 Qbot intrusion that escalated to domain compromise via Zerologon, with Cobalt Strike deployment, lateral movement, and data exfiltration. The report publicly revealed technical details of the attack chain and defender observations.
Microsoft announced plans to reduce malware delivery through VBA Office macros. Later reporting cited this announcement as a likely driver behind Qbot operators changing delivery tactics.
Microsoft disabled Excel 4.0 (XLM) macros by default, a change noted in reporting because Qakbot campaigns had commonly abused malicious macros in Office documents. Researchers later linked Qbot delivery changes to Microsoft's macro-hardening efforts.
In November 2021, attackers gained initial access through execution of a malicious Qbot DLL on a Windows workstation, then exploited Zerologon about 30 minutes later to compromise a domain controller and obtain domain administrator access. They deployed Cobalt Strike, moved laterally, enabled RDP-related settings, and exfiltrated sensitive documents before defenders evicted them.
Technical analysis described QakBot campaigns in 2020–2021 using phishing-delivered Office documents with macros, stagers, and in-memory loaders to establish infection and contact command-and-control servers. After C2 was established, operators could push additional payloads including ransomware such as ProLock.
QakBot, also known as QBot/QuakBot/Pinkslipbot/Pinkslip, was first observed as a banking trojan targeting Windows systems. The malware was described as stealing banking credentials and evolving into a modular platform over time.
Cisco Talos reported that Qakbot-affiliated actors remained active after the late-August 2023 takedown, continuing phishing activity that delivered Ransom Knight and Remcos. Talos said it had not observed the actors distributing Qakbot malware itself after the infrastructure seizure.
After Talos published research on tracking Qakbot campaigns through LNK metadata, actors associated with the 'AA,' 'BB,' and 'Obama' campaigns began wiping metadata from LNK files. Talos nevertheless identified August 2023 LNK files created on a machine previously tied to Qakbot activity.
Cyble documented Qakbot distribution through spam emails carrying malicious OneNote attachments and ZIP archives with WSF files. The infection chains used BAT, JSE, JScript, PowerShell, and rundll32.exe to download and execute DLL payloads masquerading as benign files.
Trend Micro documented intrusion chains in which QAKBOT was used for initial access, execution, persistence, discovery, and command-and-control, while Cobalt Strike supported lateral movement and Black Basta delivered ransomware impact. The phishing lures used password-protected ZIP or HTML attachments leading to ISO files and malicious links.
Qbot operators began distributing malware through phishing emails carrying password-protected ZIP archives containing malicious MSI installer files. Reporting described this as the first observed use of MSI packages by Qbot operators and a departure from their prior reliance on malicious Office documents with macros.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceblog.talosintelligence.com
Open sourceblog.cyble.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourcethedfirreport.com
Open sourcebleepingcomputer.com
Open sourcethedfirreport.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.