QakBot (also known as Qbot or Pinkslipbot) is a sophisticated malware that originated in 2008 as a banking trojan but evolved into a multi-purpose cybercriminal tool.
Core Capabilities
• Financial data theft: Steals banking credentials, credit card details, and personal data through browser cache scanning and keylogging.
• Network propagation: Spreads laterally via network shares, PowerShell scripts, and the Mimikatz exploit kit to compromise entire networks.
• Modular payload delivery: Acts as a gateway for ransomware (Conti, Black Basta, REvil) and tools like Cobalt Strike or Brute Ratel.
• Email hijacking: Harvests email credentials to create convincing phishing threads for further attacks.
Synonyms:
Qbot, Pinkslipbot