Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- QakBot - S0650
- Source confidence
- Not reported
- Observed
- 2023-01-19 13:04 UTC
- Retrieved
- 2026-10-08 04:34 UTC
Name of ATT&CK software | [QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. [QakBot](https://attack.mitre.org/software/S0650) is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably [ProLock](https://attack.mit
2023/01/following-the-lnk-metadata-trail.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.