logo

Tracking 15 Years of Qakbot Development

ID: d3baf971-995c-5a20-aadd-41d8ee9b5470

STIX ID: report--d3baf971-995c-5a20-aadd-41d8ee9b5470

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report analyzes Qakbot's evolution and operational TTPs, covering its HTTP-based C2 protocol changes (from RC4 to AES and from form-encoded to JSON payloads), DGA behavior and anti-analysis fake-domain generation, use of compromised FTP servers and later direct exfiltration to C2, transitioning to using compromised hosts as relays, command obfuscation (string-to-integer mappings), and the addition of RSA signature verification to prevent tampering — providing configuration formats and artefacts useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.