Home/Threat Actor/Qakbot / Qbot Operators
Threat Actor

Qakbot / Qbot Operators

qakbot_operators · russia_speaking_organized_cybercrime · active since 2007

Qakbot / Qbot Operators (Mandiant UNC2030.

CrowdStrike Mallard Spider.

Microsoft Storm-0464.

Proofpoint distribution affiliates TA570 [presidents affiliate] and TA577 [letters affiliate]) is a Russia-speaking organized cyber-criminal cluster financially-motivated, active publicly since 2007- 2008, one of the longest-running modern-era cyber-crime clusters.

the cluster originated as a banking trojan (2007- 2018) and transitioned to loader-as-a-service operations (2019-2023) becoming the modern era's most operationally consequential financial-loader-as-a-service operator with signature affiliate relationships to Conti, REvil, ProLock, Egregor, MegaCortex, and Black Basta ransomware-as-a-service operations.

sophisticated three-tier C2 infrastructure with 853+ Tier 1 supernodes in 63 countries at peak, approximately 700,000+ globally-infected victim machines including 200,000+ in the US, ~US$58 million in documented ransom-payment fees received by cluster administrators October 2021 - April 2023; FBI-led international multi-agency Operation Duck Hunt (August 25-29, 2023) achieved seizure of 52 C2 servers, US$8.6 million in cryptocurrency, ~6.5 million stolen- credential records, and systematic uninstallation of Qakbot malware from victim machines via custom uninstaller (SHA-256 7cdee5a583eacf24b1f142413aabb4e556ccf4ef3a4764ad084c1526cc90e117); described by US Attorney as "the most significant technological and financial operation ever led by the Department of Justice against a botnet" but resulted in no arrests, with continuing distribution-affiliate operations subsequently delivering DarkGate, IcedID, Pikabot, Brute Ratel, and Ransom Knight payloads from September 2023 onward.

russia_speaking_organized_cybercrime confidence: high 21 aliases MITRE ATT&CK G1037 ↗

Profile

Qakbot / Qbot Operators (also tracked as Pinkslipbot, Quakbot, Quackbot, Oakboat, historical Feodo overlap.

Proofpoint distribution-affiliate naming TA570 [presidents affiliate] and TA577 [letters affiliate].

CrowdStrike Mallard Spider; Mandiant UNC2030.

Microsoft Storm-0464) is a Russia-speaking organized cyber-criminal cluster financially-motivated, active publicly since at least 2007-2008, one of the longest-running and most operationally consequential financially-motivated organized cyber-criminal clusters tracked across modern cyber-threat-intelligence history. The cluster's signature malware family (Qakbot) is operationally cluster-defining, the cluster is consistently identified across industry vendor reporting by the signature malware family, and the cluster's operational identity is fundamentally tied to the Qakbot malware-loader operational capability. Operational phases of the cluster's longitudinal history: (1) BANKING TROJAN ERA (2007-2018). Foundational operational era as a banking trojan targeting financial-institution customer credentials for account-takeover fraud. Signature tradecraft included browser-injection, form-grabber, and web-session-cookie-theft tradecraft for capturing online- banking credentials. The banking-trojan-focused operational period sustained approximately the first decade of cluster operations and established the operational pattern of sophisticated multi-tier C2 infrastructure and high-volume spam-distribution capability that subsequently distinguished the cluster from competing organized-cybercrime malware families. (2) LOADER-AS-A-SERVICE TRANSITION (2019-2020). Operational transition from banking-trojan-only operations toward the loader-as-a-service operational model that subsequently dominated cluster operations through the August 2023 FBI Operation Duck Hunt takedown. The transition was driven by the broader Russia-speaking-organized-cybercrime industry shift toward ransomware-as-a-service operations: Qakbot's signature tradecraft (sophisticated three-tier C2 infrastructure, high-volume spam distribution capability, operational evasion of endpoint-detection-and-response platforms) was operationally valuable to ransomware affiliates needing reliable initial-access into target organizations. The cluster began monetizing access to compromised hosts by selling initial-access foothold to ransomware affiliate operators. ProLock and Egregor ransomware operations of late 2020 were among the earliest documented Qakbot-affiliate-ransomware relationships. (3) FLAGSHIP RANSOMWARE-AFFILIATE ECOSYSTEM ERA (2020-2023). Operationally the cluster's modern flagship operational era. The cluster operationally established signature affiliate relationships with Conti / Wizard Spider (curated separately as wizard_spider_conti.yaml), REvil / Sodinokibi (curated as revil_sodinokibi.yaml), ProLock, Egregor, MegaCortex, and subsequently Black Basta (curated as black_basta.yaml). Qakbot infections served as the operational initial-access vector for hundreds of ransomware deployments globally during this period. CISA / FBI court filings documented approximately US$58 million in ransom-payment fees received by Qakbot administrators between October 2021 and April 2023. Notable named victim sectors during this era included financial institutions on the US East Coast, a critical- infrastructure government contractor in the US Midwest, a medical device manufacturer on the US West Coast, and many additional Fortune-500-and-mid-market organizations globally. As of mid-June 2023 (~two months before the takedown), 853 Tier 1 supernodes had been identified across 63 countries, demonstrating the operational scale of cluster C2 infrastructure. (4) MICROSOFT MACRO-DISABLE ADAPTATION (2022-2023). Following Microsoft's February 2022 announcement that VBA macros would be disabled by default in Office applications starting April 2022 (and the subsequent disable of XL4 macros), the cluster operationally adapted by rapidly diversifying initial-access file-format weaponization across Microsoft OneNote files (early 2023), HTML smuggling, ZIP archives containing weaponized PDF/HTML/WSF/JavaScript files (March 2023), ISO files, IMG files, LNK files, and modified file extension obfuscation. HP Wolf Security analysis identified Qakbot as one of the most active malware families of Q2 2023, with 18 unique attack chains across 56 campaigns, operationally demonstrating the cluster's "penchant for quickly permuting tradecraft to exploit gaps in network defenses." (5) FBI OPERATION DUCK HUNT INTERNATIONAL TAKEDOWN AND POST-TAKEDOWN OPERATIONS (August 2023 onward). On August 25-29, 2023, the FBI led the international multi-agency Operation Duck Hunt coordinating with cybersecurity authorities and law enforcement from France, Germany, the Netherlands, the United Kingdom, Romania, Latvia, plus Europol and Eurojust. Operation Duck Hunt achieved seizure of 52 Qakbot C2 servers worldwide, FBI access to the Qakbot operator administrative panel and Tier 3 backend C2 server, deployment of a custom uninstaller binary via the Qakbot botnet's own command channel to systematically uninstall Qakbot malware from approximately 700,000+ globally-infected victim machines (200,000+ in the US), seizure of approximately US$8.6 million in cryptocurrency from cluster-controlled wallets, and seizure of approximately 6.5 million stolen- credential records. US Attorney Martin Estrada described Operation Duck Hunt as "the most significant technological and financial operation ever led by the Department of Justice against a botnet." Notably, Operation Duck Hunt resulted in no arrests, the operator membership remained at large, and subsequent industry reporting (Cisco Talos October 2023 Ransom Knight disclosure, TA577 DarkGate pivot September 2023, Pikabot adoption late 2023) confirmed continuing distribution-affiliate operations under affiliate- membership-pivoted operational patterns delivering DarkGate, IcedID, Pikabot, Brute Ratel, and Ransom Knight payloads in place of Qakbot from September 2023 onward.

Signature operational tradecraft includes
  • Sophisticated three-tier C2 infrastructure: bots communicate with Tier 1 supernodes (compromised victim machines promoted to supernode role by downloading additional software modules), which relay to Tier 2 proxy servers, which relay to Tier 3 backend C2 servers controlled by cluster operators. The three-tier architecture provides operational resilience and concealment of the main C2 backend, and is one of the most sophisticated C2 architectures observed across modern organized-cybercrime malware families.
  • High-volume email-spam-distribution capability with multi- format weaponized attachments (VBA macros 2007-2022, OneNote early 2023, HTML smuggling 2022-2023, ZIP+PDF+HTML+WSF+JS compound payloads 2023, ISO/IMG/LNK 2022-2023).
  • Registry-Run-Key persistence (T1547.001) with frequent randomization of run-key value names and target binary paths to evade signature-based detection.
  • DLL-loader operational pattern: Qakbot is operationally packaged as a DLL loaded by rundll32.exe with randomized export-function names, the operational pattern enables the cluster to evade endpoint-detection-and-response platform signatures focused on PE-executable static-analysis.
  • Affiliate-distribution model with two operationally most- active historical affiliates: TA570 ("presidents" affiliate, US-president-themed campaign IDs e.g. obama225) and TA577 ("letters" affiliate, letter-code campaign IDs e.g. AA, BB, TR).
  • Anti-analysis and anti-VM/sandbox tradecraft sophisticated across the cluster's operational history. The cluster is operationally significant as the modern era's most operationally consequential financial-loader-as-a-service operator across approximately 16 years of operational continuity, with a documented direct operational role in hundreds of ransomware deployments globally, US$58 million in documented ransom-payment fees received by cluster administrators in approximately 18 months 2021-2023, and approximately 700,000+ globally-infected victim machines at the time of the August 2023 takedown. The FBI Operation Duck Hunt takedown is one of the most operationally significant US-government disruption operations against organized- cybercrime malware operations in modern cyber-threat- intelligence history, alongside the January 2021 Europol/FBI Emotet takedown (curated separately as emotet_operators.yaml in this corpus). The two takedown operations together operationally demonstrated that international multi-agency law-enforcement coordination can disrupt operationally- productive Russia-speaking-organized-cybercrime malware operations even in the absence of operator-membership arrests, though the post-takedown continuing operations observed for both Emotet (November 2021 onward) and Qakbot (September 2023 onward) demonstrate that infrastructure disruption alone is insufficient for permanent operational defeat absent operator-membership prosecution.

Aliases

21
qakbotqbotq-botquakbotquackbotpinkslipbotpink slipbotoakboatfeodota570ta577mallard spidermallard-spiderunc2030unc-2030storm-0464storm0464qakbot_operatorsqakbot operatorsqakbot gangqbot operators

Notable Campaigns

9
2024-presentLimited Qakbot Resurfacing and Affiliate-Pivoted Operations (2024-Present)
2023FBI Operation Duck Hunt International Takedown (August 25-29, 2023)
2023Post-Takedown Ransom Knight Distribution via Qakbot Affiliate Phishing (October 2023)
2022-2023Microsoft Macro-Disable Adaptation: Multi-Format Weaponization (2022-2023)
2022-2023Black Basta Ransomware Affiliate Relationship (2022-2023)
2020-2023TA570 + TA577 Distribution Affiliate Operational Pattern (2020-2023)
2020-2022Conti + REvil Ransomware Affiliate Relationships (2020-2022)
2019-2020Loader-as-a-Service Operational Transition (2019-2020)
2007-2008Qakbot / Qbot Banking Trojan Operational Emergence (2007-2008)

Attribution & Reporting

Attributed by
FBIUS CISAUS Department of JusticeEuropolEurojustUK National Crime Agency (NCA)French National Cybersecurity Agency (ANSSI)German Federal Criminal Police Office (BKA)Netherlands National PoliceRomanian DIICOTLatvian State PoliceCrowdStrikeMandiantProofpointMicrosoft Threat Intelligence CenterCisco TalosSecureWorks Counter Threat UnitRed CanaryTrend MicroZscaler ThreatLabzSpamhausAbuse.chHP Wolf SecurityReliaQuestDeutsche Telekom CERT
Key reporting
reportCISA + FBI AA23-242A: Identification and Disruption of QakBot Infrastructure (August 30, 2023), canonical US-government formal-attribution publication
reportUS Department of Justice (Central District of California): Qakbot Malware Disrupted in International Cyber Takedown (August 29, 2023)
reportEuropol: Qakbot Botnet Infrastructure Shattered After International Operation (August 29, 2023)
reportCisco Talos: Qakbot-Affiliated Actors Distribute Ransom Knight Malware (October 5, 2023), canonical post-takedown affiliate-persistence disclosure
reportRed Canary Threat Detection Report: Qbot Threat Profile (multiple years), canonical industry vendor profile
reportProofpoint: TA570 'Presidents' Affiliate Operational Profile (multiple years)
reportProofpoint: TA577 'Letters' Affiliate Operational Profile + DarkGate Pivot (September 2023)
reportDeutsche Telekom CERT CTI Team: TA577 DarkGate Phishing Campaign (September 22, 2023)
reportZscaler ThreatLabz: Technical Analysis of Qakbot Banker (July 2023)
reportSecureWorks Counter Threat Unit: Qakbot Shutdown Shellcode Distribution (August 25, 2023)
reportHP Wolf Security: Q2 2023 Threat Insights, Qakbot Multi-Format Weaponization Analysis
reportMandiant: UNC2030 Operational Tracking (Qakbot operator umbrella)
reportCrowdStrike: Mallard Spider Operational Profile (Qakbot operator umbrella)
reportMicrosoft Threat Intelligence: Storm-0464 Tracking (recent Qakbot-related operations)
reportTrend Micro: Qakbot Continued Operational Tracking
reportSpamhaus + Abuse.ch: Qakbot Infrastructure Tracking (multiple years, Q3 2023 -41% post-takedown infrastructure decrease)
reportReliaQuest: Qakbot Top Malware Loader Tracking (first half of 2023)
reportUK National Crime Agency Statement: Operation Duck Hunt International Cooperation (August 2023)
reportMalpedia Malware Profile: Win.Qakbot
reportMITRE ATT&CK Software S0650, Qakbot

Operational

State sponsor

Russia-speaking organized cyber-criminal cluster, financially- motivated. The cluster's longitudinal operational pattern, the Russian-language artifacts found in malware variants across the operational history, infrastructure-provider patterns, and operational coordination with the broader Russia-speaking- organized-cybercrime ransomware ecosystem (Conti, REvil, Egregor, ProLock, MegaCortex, Black Basta affiliate distribution relationships) are all operationally consistent with attribution to Russia-speaking organized cybercrime operating from Russia or adjacent CIS countries. No formal government cybersecurity attribution to a specific state actor has been asserted.

the cluster has not been linked to state intelligence services and is consistently tracked across industry vendor reporting (CrowdStrike, Mandiant, Proofpoint, Microsoft, Cisco Talos, SecureWorks, Red Canary, Trend Micro, Zscaler) as financially-motivated organized cybercrime. The cluster's operational sophistication (three-tier C2 infrastructure with 853+ supernodes in 63 countries as of mid-2023, sustained operational tempo across approximately 16 years, hundreds of millions of dollars in cumulative losses) is operationally distinctive among organized-cybercrime malware-loader operators. The August 2023 FBI Operation Duck Hunt takedown did not result in arrests.

the operator membership remained at large, and industry reporting (Cisco Talos October 2023, Red Canary, Deutsche Telekom CERT September 2023) confirmed continuing operations under affiliate-membership-pivoted operational patterns delivering Ransom Knight, DarkGate, IcedID, and Pikabot payloads in place of Qakbot from approximately September-October 2023 onward. The operator membership relationships with the Conti / Black Basta / Wizard Spider ransomware ecosystem are operationally significant: Qakbot operations were a primary initial-access vector for multiple ransomware affiliates under the broader Russia-speaking- organized-cybercrime umbrella. Wizard Spider / Conti operations are curated separately in this corpus as wizard_spider_conti.yaml.

Black Basta is curated as black_basta.yaml.

Motivations
banking_credential_theft_historical_2007_2019, financial_fraud, access_resale_to_ransomware_affiliates, loader_as_a_service_revenue_2019_2023, credential_and_data_exfiltration_for_extortion
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGACORTEX RANSOMWARESHARPHOUND
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin