logo

How STRIKE Helped Identify Qakbot’s Alleged Operator and Support a $24M Asset Seizure

ID: 350f64bb-c2b1-5372-9e31-d61421c7a936

STIX ID: report--350f64bb-c2b1-5372-9e31-d61421c7a936

Feed Name: SecurityScorecard Blog

Threat Score
78/100

Date Published: 2025-05-23

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE team supported multinational law enforcement in the investigation and attribution of Qakbot, a long-running malware platform used since 2008 as a first-stage loader for numerous ransomware groups. The DOJ unsealed an indictment against an alleged Qakbot operator, Rustam Gallyamov, and pursued civil forfeiture of millions in cryptocurrency; the report details prior takedowns (including seizures in 2023 and 2024/2025), the actors’ shift to spam-bomb campaigns after infrastructure disruption, and STRIKE’s infrastructure tracking and TTP analysis that contributed to the case.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.