logo

Qakbot Upgrades to Stealthier Persistence Method

ID: aac96d8d-c0d3-5590-91c4-935b5b2e40e3

STIX ID: report--aac96d8d-c0d3-5590-91c4-935b5b2e40e3

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Qakbot (a versatile banking trojan) has been updated to combine its loader and bot into a single DLL, employ stealthy delivery via Excel 4 macros distributed by spam campaigns, and shift runtime configuration/logging into encrypted registry entries; post-compromise activity includes deploying Cobalt Strike and ransomware families (ProLock, Egregor). The report describes infection flow, evasive persistence (scheduled tasks, dynamic Run key installation on shutdown/resume), low initial AV detection rates, and provides IoCs and a scheduled task example.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.