Qakbot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
October 23, 2025
Last Seen
July 5, 2026

Qakbot is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 5, 2026.

Overview

Qakbot (also known as Qbot) is a long-running, modular banking trojan/botnet used for credential theft and financial fraud, often delivering additional payloads via phishing and compromised documents. It relies on a robust command-and-control infrastructure and evolves to evade detection, making it a persistent and high-impact threat in cybersecurity.

Related Threat Clusters

  • Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

    Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…

    4 articles · Updated June 23, 2026
  • Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers

    A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…

    7 articles · Updated July 1, 2026
  • Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware

    Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…

    8 articles · Updated April 17, 2026
  • Russian Access Broker Sentenced for $9M Ransomware Facilitation

    Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…

    21 articles · Updated March 24, 2026
  • US Government Agency Paid $1M to Data Extortion Group Kairos

    A U.S. government entity reportedly paid $1 million to the Kairos extortion group to prevent the public release of sensitive data. The payment was revealed in a Ransom-ISAC case study, which utilized a leaked…

    9 articles · Updated July 4, 2026
  • Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

    The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…

    9 articles · Updated February 9, 2026
  • Russia's Cybercrime Landscape Shifts Amid Law Enforcement Actions

    Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…

    2 articles · Updated January 9, 2026
  • Aeternum Botnet Utilizes Polygon Blockchain for Command Control

    The Aeternum botnet loader has been identified as using Polygon smart contracts for its command-and-control (C2) operations, moving away from traditional centralized servers. This shift complicates efforts by…

    9 articles · Updated February 26, 2026
  • Operation Endgame 3.0 Disrupts Major Malware Networks

    Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…

    20 articles · Updated November 24, 2025

Recent Intelligence Reports

  • A Huge Trove Of Leaked Black Basta Chat Logs Expose The Ransomware Gangs Key Members And Victims — techcrunch.com · July 5, 2026
  • 012 — attack.mitre.org · July 1, 2026
  • [SecurityIntel] 24 Jun | Active Exploitation of Cisco CM and Samsung KNOX — Buttondown · June 24, 2026
  • Quick Assist abuse — www.google.com · April 17, 2026
  • Manager of botnet used in ransomware attacks gets 2 years in prison — Bleepingcomputer · March 25, 2026
  • Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features — Cybersecuritynews · February 27, 2026
  • Aeternum Botnet Shifts Command Control to Polygon Blockchain — Infosecurity-Magazine · February 26, 2026
  • Black Basta: Defense Evasion Capability Embedded in Ransomware Payload — Security · February 5, 2026

CVSS v3.1 Breakdown