S0650: QakBot
Security context for executives and security teams
S0650: QakBot describes [QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. [QakBot](https://attack.mitre.org/software/S0650) is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably [ProLock](https://attack.mitre.org/software/S0654) and [Egregor](https://attack.mitre.org/software/S0554).(Citation: Trend Micro Qakbot December 2020)(Citation: Red Canary Qb...
Executive priority
S0650: QakBot is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0650: QakBot by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0650: QakBot appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
QakBot
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1218.010 | Regsvr32Sub-technique | |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | QakBot has placed its payload in hidden subdirectories.CitationTrend Micro Black Basta October 2022 |
| Enterprise | T1497.001 | System ChecksSub-technique | |
| Enterprise | T1018 | Remote System Discovery | |
| Enterprise | T1005 | Data from Local System | |
| Enterprise | T1090.002 | External ProxySub-technique | |
| Enterprise | T1059.001 | PowerShellSub-technique | QakBot can use PowerShell to download and execute payloads.CitationGroup IB Ransomware September 2020 |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | |
| Enterprise | T1106 | Native API | |
| Enterprise | T1027.001 | Binary PaddingSub-technique | QakBot can use large file sizes to evade detection.CitationTrend Micro Qakbot May 2020CitationGroup IB Ransomware September 2020 |
| Enterprise | T1543.003 | Windows ServiceSub-technique | QakBot can remotely create a temporary service on a target host.CitationNCC Group Black Basta June 2022 |
| Enterprise | T1568.002 | Domain Generation AlgorithmsSub-technique | QakBot can use domain generation algorithms in C2 communication.CitationTrend Micro Qakbot May 2020 |
| Enterprise | T1685 | Disable or Modify Tools | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.CitationGroup IB Ransomware September 2020 |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | |
| Enterprise | T1027.011 | Fileless StorageSub-technique | |
| Enterprise | T1036.008 | Masquerade File TypeSub-technique | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022 |
| Enterprise | T1135 | Network Share Discovery | |
| Enterprise | T1055.012 | Process HollowingSub-technique | |
| Enterprise | T1059.007 | JavaScriptSub-technique | |
| Enterprise | T1218.007 | MsiexecSub-technique | QakBot can use MSIExec to spawn multiple cmd.exe processes.CitationCrowdstrike Qakbot October 2020 |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | |
| Enterprise | T1204.001 | Malicious LinkSub-technique | |
| Enterprise | T1124 | System Time Discovery | |
| Enterprise | T1204.002 | Malicious FileSub-technique | QakBot has gained execution through users opening malicious attachments.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[1]CitationCyberint Qakbot May 2021[4][3]CitationGroup IB Ransomware September 2020CitationDeep Instinct Black Basta August 2022CitationMicrosoft Ransomware as a Service |
| Enterprise | T1041 | Exfiltration Over C2 Channel | |
| Enterprise | T1033 | System Owner/User Discovery | |
| Enterprise | T1027.006 | HTML SmugglingSub-technique | QakBot has been delivered in ZIP files via HTML smuggling.CitationTrend Micro Black Basta October 2022CitationDeep Instinct Black Basta August 2022 |
| Enterprise | T1016.001 | Internet Connection DiscoverySub-technique | |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | QakBot can use obfuscated and encoded scripts.CitationCyberint Qakbot May 2021CitationTrend Micro Black Basta October 2022 |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | |
| Enterprise | T1553.002 | Code SigningSub-technique | |
| Enterprise | T1027 | Obfuscated Files or Information | QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.CitationCyberint Qakbot May 2021 |
| Enterprise | T1057 | Process Discovery | |
| Enterprise | T1069.001 | Local GroupsSub-technique | |
| Enterprise | T1574.001 | DLLSub-technique | QakBot has the ability to use DLL side-loading for execution.CitationDeep Instinct Black Basta August 2022 |
| Enterprise | T1016 | System Network Configuration Discovery | |
| Enterprise | T1539 | Steal Web Session Cookie | |
| Enterprise | T1055 | Process Injection | |
| Enterprise | T1482 | Domain Trust Discovery | |
| Enterprise | T1074.001 | Local Data StagingSub-technique | QakBot has stored stolen emails and other data into new folders prior to exfiltration.CitationKroll Qakbot June 2020 |
| Enterprise | T1110 | Brute Force | |
| Enterprise | T1553.005 | Mark-of-the-Web BypassSub-technique | QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.CitationTrend Micro Black Basta October 2022 |
| Enterprise | T1185 | Browser Session Hijacking | |
| Enterprise | T1497.003 | Time Based ChecksSub-technique | |
| Enterprise | T1105 | Ingress Tool Transfer | |
| Enterprise | T1120 | Peripheral Device Discovery | QakBot can identify peripheral devices on targeted systems.CitationTrend Micro Qakbot May 2020 |
| Enterprise | T1095 | Non-Application Layer Protocol | |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | |
| Enterprise | T1027.005 | Indicator Removal from ToolsSub-technique | QakBot can make small changes to itself in order to change its checksum and hash value.CitationCrowdstrike Qakbot October 2020CitationCyberint Qakbot May 2021 |
| Enterprise | T1112 | Modify Registry | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1056.001 | KeyloggingSub-technique | |
| Enterprise | T1091 | Replication Through Removable Media | QakBot has the ability to use removable drives to spread through compromised networks.CitationTrend Micro Qakbot May 2020 |
| Enterprise | T1132.001 | Standard EncodingSub-technique | |
| Enterprise | T1059.005 | Visual BasicSub-technique | |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1047 | Windows Management Instrumentation | |
| Enterprise | T1010 | Application Window Discovery | |
| Enterprise | T1518 | Software Discovery | QakBot can enumerate a list of installed programs.CitationGroup IB Ransomware September 2020 |
| Enterprise | T1049 | System Network Connections Discovery | |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1218.011 | Rundll32Sub-technique | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.CitationCrowdstrike Qakbot October 2020[2]CitationCyberint Qakbot May 2021[4]CitationTrend Micro Black Basta October 2022 |
| Enterprise | T1572 | Protocol Tunneling | |
| Enterprise | T1555.003 | Credentials from Web BrowsersSub-technique | |
| Enterprise | T1027.002 | Software PackingSub-technique | QakBot can encrypt and pack malicious payloads.CitationCyberint Qakbot May 2021 |
| Enterprise | T1070.004 | File DeletionSub-technique | |
| Enterprise | T1210 | Exploitation of Remote Services | QakBot can move laterally using worm-like functionality through exploitation of SMB.CitationCrowdstrike Qakbot October 2020 |
Groups, software, and campaigns
G1037: TA577
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.[1]
G1046: Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]
G0127: TA551
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.3 | Current bundle | dba2548fa183… | ||
| 19.1 | 1.3 | Older bundle | dba2548fa183… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Trend Micro Qakbot December 2020
Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.
Open source URL - [2]Red Canary Qbot
Rainey, K. (n.d.). Qbot. Retrieved September 27, 2021.
Open source URL - [3]Kaspersky QakBot September 2021
Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.
Open source URL - [4]ATT QakBot April 2021
Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.
Open source URL - [5]Pinkslipbot
(Citation: Kaspersky QakBot September 2021)(Citation: ATT QakBot April 2021)
- [6]QBot
(Citation: Trend Micro Qakbot December 2020)(Citation: Red Canary Qbot)(Citation: Kaspersky QakBot September 2021)(Citation: ATT QakBot April 2021)
- [7]QuackBot
(Citation: Kaspersky QakBot September 2021)
- [8]mitre-attackS0650Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
