Qakbot

Qakbot — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

QakbotConfidence: High

Botnet / malware operator
Also known as: Pinkslipbot, QBot

Motivation: Financial

1Attributed Breaches
HighAttribution Confidence
Botnet / malware operatorActor Type

Overview

Operators of the Qakbot banking-trojan-turned-loader, active since 2007-2008 before becoming a major ransomware-delivery and access-broker botnet. Dismantled in the August 2023 multinational Operation Duck Hunt (700k+ infected machines, $8.6M+ extorted); delivered via malspam.

Tactics, Targeting & TTPs

Delivered via malspam; used to drop ransomware and act as a RAT. DOJ/Europol seized infrastructure in 2023 (700k+ infected machines; $8.6M+ extorted).

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation