Motivation: Financial
Operators of the Qakbot banking-trojan-turned-loader, active since 2007-2008 before becoming a major ransomware-delivery and access-broker botnet. Dismantled in the August 2023 multinational Operation Duck Hunt (700k+ infected machines, $8.6M+ extorted); delivered via malspam.
Delivered via malspam; used to drop ransomware and act as a RAT. DOJ/Europol seized infrastructure in 2023 (700k+ infected machines; $8.6M+ extorted).
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.