LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

EnterpriseS0650MalwareObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0650: QakBot describes [QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. [QakBot](https://attack.mitre.org/software/S0650) is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably [ProLock](https://attack.mitre.org/software/S0654) and [Egregor](https://attack.mitre.org/software/S0554).(Citation: Trend Micro Qakbot December 2020)(Citation: Red Canary Qb...

Executive priority

S0650: QakBot is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0650: QakBot by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0650: QakBot appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

71 rows
DomainIDNameRelationship / procedure
EnterpriseT1218.010Regsvr32Sub-technique

QakBot can use Regsvr32 to execute malicious DLLs.[2]CitationCyberint Qakbot May 2021[4]CitationTrend Micro Black Basta October 2022CitationNCC Group Black Basta June 2022CitationDeep Instinct Black Basta August 2022

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

QakBot has placed its payload in hidden subdirectories.CitationTrend Micro Black Basta October 2022

EnterpriseT1497.001System ChecksSub-technique

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.CitationTrend Micro Qakbot May 2020[4]

EnterpriseT1018Remote System Discovery

QakBot can identify remote systems through the net view command.CitationCrowdstrike Qakbot October 2020[3]CitationTrend Micro Black Basta October 2022

EnterpriseT1005Data from Local System

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.[2][3]

EnterpriseT1090.002External ProxySub-technique

QakBot has a module that can proxy C2 communications.[3]

EnterpriseT1059.001PowerShellSub-technique

QakBot can use PowerShell to download and execute payloads.CitationGroup IB Ransomware September 2020

EnterpriseT1059.003Windows Command ShellSub-technique

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.CitationCrowdstrike Qakbot October 2020[4][3]CitationTrend Micro Black Basta October 2022

EnterpriseT1518.001Security Software DiscoverySub-technique

QakBot can identify the installed antivirus product on a targeted system.CitationCrowdstrike Qakbot October 2020[4][4][3]

EnterpriseT1106Native API

QakBot can use GetProcAddress to help delete malicious strings from memory.[4]

EnterpriseT1027.001Binary PaddingSub-technique

QakBot can use large file sizes to evade detection.CitationTrend Micro Qakbot May 2020CitationGroup IB Ransomware September 2020

EnterpriseT1543.003Windows ServiceSub-technique

QakBot can remotely create a temporary service on a target host.CitationNCC Group Black Basta June 2022

EnterpriseT1568.002Domain Generation AlgorithmsSub-technique

QakBot can use domain generation algorithms in C2 communication.CitationTrend Micro Qakbot May 2020

EnterpriseT1685Disable or Modify Tools

QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.CitationGroup IB Ransomware September 2020

EnterpriseT1083File and Directory Discovery

QakBot can identify whether it has been run previously on a host by checking for a specified folder.[4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

QakBot can maintain persistence by creating an auto-run Registry key.CitationTrend Micro Qakbot May 2020CitationCrowdstrike Qakbot October 2020[1]CitationGroup IB Ransomware September 2020

EnterpriseT1027.011Fileless StorageSub-technique

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.[2]CitationGroup IB Ransomware September 2020

EnterpriseT1036.008Masquerade File TypeSub-technique

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022

EnterpriseT1135Network Share Discovery

QakBot can use net share to identify network shares for use in lateral movement.CitationTrend Micro Qakbot May 2020[3]

EnterpriseT1055.012Process HollowingSub-technique

QakBot can use process hollowing to execute its main payload.[4]

EnterpriseT1059.007JavaScriptSub-technique

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.[3]CitationTrend Micro Black Basta October 2022

EnterpriseT1218.007MsiexecSub-technique

QakBot can use MSIExec to spawn multiple cmd.exe processes.CitationCrowdstrike Qakbot October 2020

EnterpriseT1140Deobfuscate/Decode Files or Information

QakBot can deobfuscate and re-assemble code strings for execution.CitationCyberint Qakbot May 2021[4][3]

EnterpriseT1114.001Local Email CollectionSub-technique

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.CitationKroll Qakbot June 2020[1][3]

EnterpriseT1204.001Malicious LinkSub-technique

QakBot has gained execution through users opening malicious links.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020[1][4][3]CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022

EnterpriseT1124System Time Discovery

QakBot can identify the system time on a targeted host.[3]

EnterpriseT1204.002Malicious FileSub-technique

QakBot has gained execution through users opening malicious attachments.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[1]CitationCyberint Qakbot May 2021[4][3]CitationGroup IB Ransomware September 2020CitationDeep Instinct Black Basta August 2022CitationMicrosoft Ransomware as a Service

EnterpriseT1041Exfiltration Over C2 Channel

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.[3]

EnterpriseT1033System Owner/User Discovery

QakBot can identify the user name on a compromised system.[3]CitationTrend Micro Black Basta October 2022

EnterpriseT1027.006HTML SmugglingSub-technique

QakBot has been delivered in ZIP files via HTML smuggling.CitationTrend Micro Black Basta October 2022CitationDeep Instinct Black Basta August 2022

EnterpriseT1016.001Internet Connection DiscoverySub-technique

QakBot can measure the download speed on a targeted host.[3]

EnterpriseT1573.001Symmetric CryptographySub-technique

QakBot can RC4 encrypt strings in C2 communication.[3]

EnterpriseT1027.010Command ObfuscationSub-technique

QakBot can use obfuscated and encoded scripts.CitationCyberint Qakbot May 2021CitationTrend Micro Black Basta October 2022

EnterpriseT1071.001Web ProtocolsSub-technique

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.CitationTrend Micro Qakbot May 2020CitationCrowdstrike Qakbot October 2020[3]

EnterpriseT1553.002Code SigningSub-technique

QakBot can use signed loaders to evade detection.[4]CitationDeep Instinct Black Basta August 2022

EnterpriseT1027Obfuscated Files or Information

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.CitationCyberint Qakbot May 2021

EnterpriseT1057Process Discovery

QakBot has the ability to check running processes.[4]

EnterpriseT1069.001Local GroupsSub-technique

QakBot can use net localgroup to enable discovery of local groups.[3]CitationTrend Micro Black Basta October 2022

EnterpriseT1574.001DLLSub-technique

QakBot has the ability to use DLL side-loading for execution.CitationDeep Instinct Black Basta August 2022

EnterpriseT1016System Network Configuration Discovery

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.CitationCrowdstrike Qakbot October 2020[3]CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022CitationMicrosoft Ransomware as a Service

EnterpriseT1539Steal Web Session Cookie

QakBot has the ability to capture web session cookies.CitationKroll Qakbot June 2020[3]

EnterpriseT1055Process Injection

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020[1][3]CitationTrend Micro Black Basta October 2022

EnterpriseT1482Domain Trust Discovery

QakBot can run nltest /domain_trusts /all_trusts for domain trust discovery.[3]

EnterpriseT1074.001Local Data StagingSub-technique

QakBot has stored stolen emails and other data into new folders prior to exfiltration.CitationKroll Qakbot June 2020

EnterpriseT1110Brute Force

QakBot can conduct brute force attacks to capture credentials.CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[3]

EnterpriseT1553.005Mark-of-the-Web BypassSub-technique

QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.CitationTrend Micro Black Basta October 2022

EnterpriseT1185Browser Session Hijacking

QakBot can use advanced web injects to steal web banking credentials.CitationCyberint Qakbot May 2021[3]

EnterpriseT1497.003Time Based ChecksSub-technique

The QakBot dropper can delay dropping the payload to evade detection.CitationCyberint Qakbot May 2021[3]

EnterpriseT1105Ingress Tool Transfer

QakBot has the ability to download additional components and malware.CitationTrend Micro Qakbot May 2020CitationCrowdstrike Qakbot October 2020[1]CitationCyberint Qakbot May 2021[3]CitationGroup IB Ransomware September 2020

EnterpriseT1120Peripheral Device Discovery

QakBot can identify peripheral devices on targeted systems.CitationTrend Micro Qakbot May 2020

EnterpriseT1095Non-Application Layer Protocol

QakBot has the ability use TCP to send or receive C2 packets.[3]

EnterpriseT1566.002Spearphishing LinkSub-technique

QakBot has spread through emails with malicious links.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020[1][4][3]CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022

EnterpriseT1027.005Indicator Removal from ToolsSub-technique

QakBot can make small changes to itself in order to change its checksum and hash value.CitationCrowdstrike Qakbot October 2020CitationCyberint Qakbot May 2021

EnterpriseT1112Modify Registry

QakBot can modify the Registry to store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.[2]CitationGroup IB Ransomware September 2020

EnterpriseT1566.001Spearphishing AttachmentSub-technique

QakBot has spread through emails with malicious attachments.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020[1]CitationCyberint Qakbot May 2021[4][3]CitationGroup IB Ransomware September 2020CitationDeep Instinct Black Basta August 2022CitationMicrosoft Ransomware as a Service

EnterpriseT1056.001KeyloggingSub-technique

QakBot can capture keystrokes on a compromised host.CitationKroll Qakbot June 2020[1][3]

EnterpriseT1091Replication Through Removable Media

QakBot has the ability to use removable drives to spread through compromised networks.CitationTrend Micro Qakbot May 2020

EnterpriseT1132.001Standard EncodingSub-technique

QakBot can Base64 encode system information sent to C2.CitationCrowdstrike Qakbot October 2020[3]

EnterpriseT1059.005Visual BasicSub-technique

QakBot can use VBS to download and execute malicious files.CitationTrend Micro Qakbot May 2020 CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[1]CitationCyberint Qakbot May 2021CitationGroup IB Ransomware September 2020CitationTrend Micro Black Basta October 2022

EnterpriseT1082System Information Discovery

QakBot can collect system information including the OS version and domain on a compromised host.CitationCrowdstrike Qakbot October 2020[4]CitationGroup IB Ransomware September 2020CitationMicrosoft Ransomware as a Service

EnterpriseT1047Windows Management Instrumentation

QakBot can execute WMI queries to gather information.[3]

EnterpriseT1010Application Window Discovery

QakBot has the ability to enumerate windows on a compromised host.[4]

EnterpriseT1518Software Discovery

QakBot can enumerate a list of installed programs.CitationGroup IB Ransomware September 2020

EnterpriseT1049System Network Connections Discovery

QakBot can use netstat to enumerate current network connections.[3]CitationTrend Micro Black Basta October 2022

EnterpriseT1053.005Scheduled TaskSub-technique

QakBot has the ability to create scheduled tasks for persistence.CitationTrend Micro Qakbot May 2020CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[1][2]CitationCyberint Qakbot May 2021[3]CitationGroup IB Ransomware September 2020

EnterpriseT1218.011Rundll32Sub-technique

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.CitationCrowdstrike Qakbot October 2020[2]CitationCyberint Qakbot May 2021[4]CitationTrend Micro Black Basta October 2022

EnterpriseT1572Protocol Tunneling

The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol.[3]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

QakBot has collected usernames and passwords from Firefox and Chrome.[3]

EnterpriseT1027.002Software PackingSub-technique

QakBot can encrypt and pack malicious payloads.CitationCyberint Qakbot May 2021

EnterpriseT1070.004File DeletionSub-technique

QakBot can delete folders and files including overwriting its executable with legitimate programs.CitationKroll Qakbot June 2020CitationCrowdstrike Qakbot October 2020[4]CitationGroup IB Ransomware September 2020

EnterpriseT1210Exploitation of Remote Services

QakBot can move laterally using worm-like functionality through exploitation of SMB.CitationCrowdstrike Qakbot October 2020

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0127: TA551

TA551 is a financially-motivated threat group that has been active since at least 2018. [1] The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. [2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.3
Created
Modified
Raw hash
dba2548fa18345cb...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.3Current bundledba2548fa183…
19.11.3Older bundledba2548fa183…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Trend Micro Qakbot December 2020

    Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.

    Open source URL
  2. [2]
    Red Canary Qbot

    Rainey, K. (n.d.). Qbot. Retrieved September 27, 2021.

    Open source URL
  3. [3]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  4. [4]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  5. [5]
    Pinkslipbot

    (Citation: Kaspersky QakBot September 2021)(Citation: ATT QakBot April 2021)

  6. [6]
    QBot

    (Citation: Trend Micro Qakbot December 2020)(Citation: Red Canary Qbot)(Citation: Kaspersky QakBot September 2021)(Citation: ATT QakBot April 2021)

  7. [7]
    QuackBot

    (Citation: Kaspersky QakBot September 2021)

  8. [8]
    mitre-attackS0650
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.