EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/qakbot-malware
388/430

File EL-0043HighResolvedCyberattack / Malware/Botnet

QakBot Malware

Also filed as QakBot · QakBot Trojan · QakBot Loader

QakBot is a sophisticated banking trojan and botnet malware designed for financial theft. It primarily operates by compromising endpoints through phishing campaigns and exploiting vulnerabilities. The malware is highly modular, allowing it to adapt to different banking systems and operating environments.

  • #botnet
  • #banking-trojan
  • #malware
  • #credential-theft
  • #phishing
Notoriety7/10
Event
1 Jan 2008
Disclosed
1 Jan 2010
Target
Banking and Enterprise Targets
Actor
QakBot Operators
Scale
Variable, depending on the number of compromised accounts.
Status
Resolved

01Summary

QakBot represents a significant evolution in banking malware, moving beyond simple keylogging to sophisticated credential harvesting and lateral movement. Initial infections typically occur via malicious attachments or compromised websites, establishing a persistent foothold on the victim's machine. Once established, QakBot executes modules designed to sniff credentials, intercept banking session data, and exfiltrate sensitive information. The botnet structure allows operators to remotely control infected machines, coordinating large-scale attacks against multiple financial institutions simultaneously. Its modularity and ability to evade detection made it a persistent threat for years, targeting both large enterprises and individual bank customers.

02Background

The emergence of QakBot coincided with the increasing digitalization of global finance and the rise of sophisticated phishing techniques. It capitalized on the trust placed in online banking portals, developing methods to bypass multi-factor authentication and steal session tokens. Its development marked a shift from opportunistic malware to highly targeted, financially motivated cybercrime.

03Key revelations

  1. 01The ability to bypass multi-factor authentication (MFA) through session hijacking.
  2. 02The use of modular components to adapt to different banking protocols.
  3. 03The systematic targeting of high-value corporate and financial accounts.

04Technical analysis

QakBot utilizes a multi-stage infection process. It often employs a loader component to download and execute the main payload, which is frequently polymorphic to evade signature-based detection. The malware communicates with Command and Control (C2) servers over common protocols (like HTTP/S), making detection difficult. Its core functionality includes memory scraping, browser session hijacking, and the deployment of secondary payloads, such as remote access Trojans (RATs).

Attack vector
Phishing emails, malicious websites (watering holes), and exploitation of unpatched vulnerabilities in client software.
Attack method
Botnet infection, credential harvesting, session hijacking, and data exfiltration.
Initial access
Phishing/Malicious Downloads
Lateral movement
Network scanning, exploiting internal vulnerabilities, and using stolen credentials.
Persistence
Registry modifications, scheduled tasks, and injecting into legitimate processes.
Exfiltration
Encrypted communication channels (HTTPS) to C2 servers.
Tool / malware
QakBot
Malware family
Banking Trojan / Botnet
Malware type
Stealer, Botnet, Trojan

Vulnerabilities exploited

  • Unpatched OS vulnerabilities
  • Browser vulnerabilities

MITRE ATT&CK techniques

  • T1059.003
  • T1566.001
  • T1071.001

05Threat actor

The operators are believed to be highly organized, professional cybercriminals, likely operating as a Ransomware-as-a-Service (RaaS) or specialized financial crime group. Their focus on high-value, liquid assets suggests a professional criminal enterprise rather than hacktivism.

Aliases

  • Criminal Gang

MITRE groups

  • T1071.001
  • T1566.001
  • T1059.003

Attribution sources

  • Security Vendors
  • Academic Researchers

06Victims and impact

Additional victims

  • Corporate Networks
  • Individual Users

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Banking Session Data
  • PII
  • Financial Records

Notable documents

  • Banking Credentials Dump
  • Session Tokens

08Financial damage

Damage is estimated in the hundreds of millions of dollars globally due to fraud and operational costs.

09Timeline

  1. 2008-01-01Initial reported activity and deployment of the malware.
  2. 2010-01-01Increased public awareness and security vendor reports detailing its capabilities.

10Reaction and fallout

Public reaction

The public reaction was one of increased awareness regarding online banking security, leading to greater adoption of hardware tokens and stronger password policies.

Political impact

The incident spurred regulatory bodies globally to mandate stronger authentication methods, moving away from simple passwords.

Geopolitical consequences

It highlighted the vulnerability of global financial infrastructure to non-state, financially motivated cyber actors.

11Legal

While specific criminal prosecutions are rare due to jurisdictional challenges, the incident contributed to increased international cooperation in cybercrime law enforcement.

Civil lawsuits

  • Class-action lawsuits against financial institutions for inadequate security measures.

12Aftermath

Policy changes

  • Mandatory implementation of hardware-based Multi-Factor Authentication (MFA).

Regulatory changes

  • Stricter adherence to PCI DSS (Payment Card Industry Data Security Standard) and similar financial regulations.

Security improvements

  • Implementation of behavioral biometrics and device fingerprinting.
  • Adoption of Zero Trust Network Architecture (ZTNA).

13Significance and legacy

Significance

QakBot is historically significant because it represented a major leap in cybercrime sophistication, demonstrating the ability to automate the theft of high-value, session-based credentials. It forced the financial sector to fundamentally reassess the security perimeter, moving focus from network defense to endpoint and identity protection.

Legacy

Its legacy is the permanent shift in cybersecurity focus towards identity and access management (IAM). Modern security solutions must now assume that the perimeter has been breached and focus on detecting anomalous behavior and compromised credentials.

14Disclosure and media

Authentication
Technical Analysis

Media partners

  • Kaspersky Lab
  • Trend Micro
  • Security News Outlets

Publishing organisations

  • Cybersecurity Research Firms

15Field notes

  1. 01The malware was known for its ability to operate silently in memory, making traditional antivirus detection difficult.
  2. 02It was often bundled with other, less critical malware to increase its chances of initial execution.

16Resolution

The malware's effectiveness was significantly reduced by the widespread adoption of behavioral MFA and advanced endpoint detection and response (EDR) tools.

17Sources

Official documents

  • Industry Threat Reports (e.g., Mandiant, Kaspersky)

References

  1. [1]Kaspersky Lab Threat Reports
  2. [2]Financial Sector Security Advisories
Fact sheetEL-0043

Dates

Event
1 Jan 2008
Started
1 Jan 2008
Discovered
1 Jan 2010
Disclosed
1 Jan 2010
Ongoing
No

Target

Organisation
Banking and Enterprise Targets
Type
Financial Institution
Sector
Banking
Country
Global

Actor

Name
QakBot Operators
Type
Criminal Gang
Motivation
Financial gain through banking fraud, credential theft, and corporate espionage.
Status
Active
Arrested
No
Convicted
No

Data

Volume
Variable, depending on the number of compromised accounts.
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.