Qakbot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
October 23, 2025
Last Seen
August 7, 2026

Qakbot (also known as Qbot) is a long-running, modular banking trojan/botnet used for credential theft and financial fraud, often delivering additional payloads via phishing and compromised documents.

Overview

Qakbot (also known as Qbot) is a long-running, modular banking trojan/botnet used for credential theft and financial fraud, often delivering additional payloads via phishing and compromised documents. It relies on a robust command-and-control infrastructure and evolves to evade detection, making it a persistent and high-impact threat in cybersecurity.

Related Threat Clusters

  • Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

    Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…

    4 articles · Updated June 23, 2026
  • CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws

    CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…

    2 articles · Updated August 7, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers

    A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…

    7 articles · Updated July 1, 2026
  • Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft

    A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit,…

    80 articles · Updated August 2, 2026
  • Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware

    Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…

    8 articles · Updated April 17, 2026
  • Russian Access Broker Sentenced for $9M Ransomware Facilitation

    Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…

    21 articles · Updated March 24, 2026
  • US Government Agency Paid $1M to Data Extortion Group Kairos

    A U.S. government entity reportedly paid $1 million to the Kairos extortion group to prevent the public release of sensitive data. The payment was revealed in a Ransom-ISAC case study, which utilized a leaked…

    9 articles · Updated July 4, 2026
  • OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race

    OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…

    1074 articles · Updated April 14, 2026
  • Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

    The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…

    9 articles · Updated February 9, 2026

Recent Intelligence Reports

  • [SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws — Buttondown · August 7, 2026
  • [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft — Buttondown · August 2, 2026
  • [SecurityIntel] 29 Jul | AI Models Exploit Artifactory Zero-Days to Escape — Buttondown · July 29, 2026
  • [SecurityIntel] 28 Jul | Active Zero-Day Exploitation of FastJson and Arista — Buttondown · July 28, 2026
  • T1539 — attack.mitre.org · July 23, 2026
  • 003 — attack.mitre.org · July 23, 2026
  • 002 — attack.mitre.org · July 23, 2026
  • A Huge Trove Of Leaked Black Basta Chat Logs Expose The Ransomware Gangs Key Members And Victims — techcrunch.com · July 5, 2026

CVSS v3.1 Breakdown