logo

Qakbot Strikes Back: Understanding the Threat

ID: 52afe69c-147c-5ce7-abf1-57b0b4924816

STIX ID: report--52afe69c-147c-5ce7-abf1-57b0b4924816

Feed Name: Binary Defense Blog

Threat Score
72/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

QakBot (QBot) has resurfaced after a 2023 takedown; recent samples are distributed via phishing (including IRS-themed lures), masquerade as Adobe installer UI, create restore-point-based persistence via srtasks.exe, drop a KROST.dll payload in AppData\Roaming, and execute via hidden rundll32—Binary Defense and Microsoft published behavior-based detections and Sentinel queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.