logo

QakBot Stealer from Newly Registered Domains

ID: d0bf73c9-c68a-555c-b26b-30e776bc1ca2

STIX ID: report--d0bf73c9-c68a-555c-b26b-30e776bc1ca2

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

**Zscaler ThreatLabZ analysis of a QakBot campaign:** This report describes malicious Office documents that use heavily obfuscated VBA macros to download and execute the QakBot infostealer, outlining the macro decryption routine, persistence mechanisms, AV/VM evasion checks, process injection and scheduled-task based execution, and provides multiple indicators (MD5s, newly registered domains, and C2 URLs) observed in the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.