logo

QBOT Malware Analysis

ID: d9f14862-0824-5bb9-8131-0eb2b24e8e64

STIX ID: report--d9f14862-0824-5bb9-8131-0eb2b24e8e64

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-02-14

Date Updated: 2026-04-27

...
...

Elastic Security Labs presents a detailed reverse-engineering analysis of the QBOT (Qakbot) V4 banking trojan from a recent campaign, documenting its three-stage execution (initialization, installation, communication), process injection and multi-user installation techniques, dynamic persistence, C2 protocol (encrypted JSON over HTTP/TLS), public-key message verification, string/resource/import obfuscation, and a list of extracted network infrastructure and command handlers; the report also provides YARA rules, a configuration extractor, and investigative artifacts (IOCs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.