logo

Qakbot Attacks Increasing due to Evolving Threats

ID: e55fc377-3f8f-599c-a131-de656cac3f0b

STIX ID: report--e55fc377-3f8f-599c-a131-de656cac3f0b

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz documents an active and evolving Qakbot (QBot) campaign that uses email-delivered attachments (XLSB with XLM 4.0 macros, ZIPs, LNK shortcuts) and multiple download techniques (PowerShell, curl, regsvr32/rundll32) to drop and execute obfuscated Qakbot DLLs; the report provides month-by-month changes in TTPs, multiple payload URLs, C2 IPs, file hashes, and recommended detections to block this credential-stealing threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.