Skip to main content
QUIETLYTIC
Malware

QakBot

Modular banking trojan, per MITRE ATT&CK, used by financially motivated actors since at least 2007, evolved from an information stealer into a ransomware delivery agent.

Threat Level
HIGH
Family
QakBot
Type
TROJAN
Also Known As
Pinkslipbot, QuackBot, QBot

Overview

QakBot (MITRE ATT&CK ID S0650) is a modular banking trojan that has been used primarily by financially motivated actors since at least 2007, per MITRE’s software profile. MITRE documents QakBot as continuously maintained and developed, having evolved from an information stealer into a delivery agent for ransomware — most notably ProLock and Egregor, per MITRE’s citations.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links QakBot to three distinct MITRE ATT&CK groups: TA577, Storm-1811, and TA551 — a smaller, more concentrated set than broadly shared dual-use tools like Mimikatz or Cobalt Strike, consistent with QakBot’s role as a specific delivery/access-broker malware family rather than a general-purpose post-exploitation tool.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to QakBot in our data include Application Window Discovery (T1010), Binary Padding (T1027.001), Browser Session Hijacking (T1185), Brute Force (T1110), Code Signing (T1553.002), Command Obfuscation (T1027.010), Credentials from Web Browsers (T1555.003), and DLL-based execution (T1574.001).

What we don’t have

MITRE’s ingested data confirms QakBot’s origin year (2007) directly in its description text, but doesn’t include a structured discovery-date field we can independently verify or update. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on QakBot’s operational status following widely reported law-enforcement disruption actions against its infrastructure.

Frequently Asked Questions

What is QakBot? A modular banking trojan, per MITRE ATT&CK, active since at least 2007 and used by financially motivated actors — since evolved into a ransomware delivery agent.

Does QakBot still deliver ransomware? Per MITRE’s documentation, QakBot has been used to deliver ProLock and Egregor ransomware; our data doesn’t include current operational-status information beyond what MITRE’s static reference bundle documents.

Which groups use QakBot? Per MITRE ATT&CK’s relationship data: TA577, Storm-1811, and TA551.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0650, aggregated September 14, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools