logo

Hibernating Qakbot

ID: 255879c7-afaf-5202-b65d-561df2e4a3d1

STIX ID: report--255879c7-afaf-5202-b65d-561df2e4a3d1

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report analyzes Qakbot campaigns from March–May 2023, describing evolving attack chains that use malspam and diverse file formats (PDF, HTML, OneNote, XLL, ZIP, MSI) to deliver staged loaders (obfuscated JS, WSF/HTA, PowerShell, XMLHTTP) which fetch and execute the Qakbot payload; it also documents advanced evasion techniques (DLL side-loading, conhost.exe indirect execution, scheduled tasks) and observes similarities between Qakbot and recently seen Pikabot samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.