Qakbot is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 5, 2026.
Qakbot (also known as Qbot) is a long-running, modular banking trojan/botnet used for credential theft and financial fraud, often delivering additional payloads via phishing and compromised documents. It relies on a robust command-and-control infrastructure and evolves to evade detection, making it a persistent and high-impact threat in cybersecurity.
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…
A U.S. government entity reportedly paid $1 million to the Kairos extortion group to prevent the public release of sensitive data. The payment was revealed in a Ransom-ISAC case study, which utilized a leaked…
The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
The Aeternum botnet loader has been identified as using Polygon smart contracts for its command-and-control (C2) operations, moving away from traditional centralized servers. This shift complicates efforts by…
Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…