{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T08:39:08+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"74805075704666583711cc12ded2a3dbde3d4a400be6edfa97e3e65defe0331c","kind":"reference","title":"QakBot - S0650","family":"QakBot - S0650","category":"Malware intelligence","summary":"Name of ATT&CK software | [QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. [QakBot](https://attack.mitre.org/software/S0650) is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably [ProLock](https://attack.mit","first_seen":1674133442,"last_seen":1674133442,"created_at":1791434093,"updated_at":1791434093,"source_count":1,"data":{"context":"2023/01/following-the-lnk-metadata-trail.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"QakBot - S0650\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/01/following-the-lnk-metadata-trail.json"],"filenames":[],"features":[],"related_cves":[],"labels":["QakBot - S0650"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2023/01/following-the-lnk-metadata-trail.json","source_label":"QakBot - S0650","evidence_class":"provider_reported","confidence":null,"observed_at":1674133442,"fetched_at":1791434093,"data":{"context":"2023/01/following-the-lnk-metadata-trail.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"QakBot - S0650\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/01/following-the-lnk-metadata-trail.json"],"family":"QakBot - S0650"}}],"indicators":[]}]}