S0650: QakBot
QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.CitationTrend Micro Qakbot December 2020CitationRed Canary QbotCitationKaspersky QakBot September 2021CitationATT QakBot April 2021
Security context for executives and security teams
QakBot matters because ATT&CK describes it as a long-running, modular Windows banking trojan that evolved into a delivery agent for ransomware, including ProLock and Egregor. For leaders, the key decision value is not just “malware prevention”; it is whether the organization can quickly recognize a Windows endpoint moving from infection into discovery, credential collection, persistence, command-and-control, and potential ransomware staging behavior.
Executive priority
Prioritize QakBot as a resilience and incident-readiness test case for Windows environments. The supplied relationships connect it to financially motivated activity, email-based distribution context through TA551, initial access broker context through TA577, and ransomware-linked ecosystem context through Storm-1811. Executives should ask whether SOC, identity, endpoint, email/web, and incident response teams can prove coverage for the behaviors ATT&CK associates with this malware: obfuscation, WMI execution, scheduled tasks, process injection, discovery, keylogging, local data collection, and exfiltration over C2.
Technical view
ATT&CK lists QakBot for Windows and provides no official detection text, so defenders should validate behavior-based coverage from the related techniques rather than rely on the malware name alone. Focus testing and hunts on Windows execution and persistence via WMI and Scheduled Task, stealth via obfuscated files, packing, binary padding, masqueraded file types, command obfuscation, fileless storage, and process injection/process hollowing. Discovery coverage should include application windows, user context, network configuration, internet connectivity, remote systems, and network connections. Collection and credential-risk coverage should include local data access and keylogging indicators, with network analytics for exfiltration over an existing C2 channel.
Likely telemetry
- Windows endpoint process creation, parent/child process, command-line, and script execution telemetry
- WMI activity and remote/local WMI execution records
- Windows Scheduled Task creation, modification, and execution events
- Endpoint file metadata, file writes, suspicious extensions or file-type mismatches, packed or padded binaries, and obfuscation indicators
- Memory and EDR telemetry relevant to process injection or process hollowing
Detection direction
- Do not depend on static QakBot indicators alone; ATT&CK relationships show multiple obfuscation and evasion behaviors that can change file appearance and weaken hash-based controls.
- Validate Windows behavior detections for WMI execution, scheduled task abuse, suspicious process injection or hollowing, and command obfuscation.
- Correlate discovery behaviors that may be individually noisy: user discovery, network configuration discovery, internet connectivity checks, remote system discovery, application window discovery, and network connection enumeration.
- Tune detections around legitimate administration activity, especially WMI, scheduled tasks, and network discovery commands, by using baselines for expected administrative accounts, hosts, and maintenance windows.
- Confirm visibility into collection and credential-risk behaviors such as local data access and keylogging-related signals; absence of this telemetry should be documented as a response limitation.
Mitigation priorities
- Harden and monitor Windows execution paths most relevant to the supplied relationships: WMI, Scheduled Task, script/command execution, and suspicious child-process chains.
- Reduce delivery and evasion risk with layered email/web controls, attachment and HTML handling policies, and endpoint controls that inspect behavior rather than only file hashes.
- Limit blast radius through least privilege, administrative account separation, and controls that reduce the value of captured credentials or keystrokes.
- Improve endpoint resilience with EDR coverage capable of observing process injection, process hollowing, fileless storage, and suspicious persistence activity.
- Segment critical systems and monitor internal discovery so a compromised Windows host cannot easily map or reach high-value systems.
Additional notes and limits
This take is based on ATT&CK S0650 QakBot version 1.3 and the supplied relationships. The most decision-relevant point is QakBot’s evolution from banking trojan to ransomware delivery agent and its mapped behaviors across discovery, stealth, execution, persistence, collection, credential access, and exfiltration. Because ATT&CK provides no official detection section for this object, coverage should be proven with local telemetry and behavior validation.
The supplied object lists Windows as the QakBot platform but does not specify tactics on the malware object itself and provides no official detection guidance. Related techniques include platforms beyond Windows, but those broader platforms should not be assumed for QakBot without additional evidence. This summary does not establish current activity, customer exposure, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
QakBot
QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.CitationTrend Micro Qakbot December 2020CitationRed Canary QbotCitationKaspersky QakBot September 2021CitationATT QakBot April 2021
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
