Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0650
MITRE ATT&CK Malware

QakBot (S0650)

PinkslipbotQuackBotQBot
ShareXLinkedInRedditHN

[QakBot](https://attack.mitre.org/software/S0650) is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. [QakBot](https://attack.mitre.org/software/S0650) is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably [ProLock](https://attack.mitre.org/software/S0654) and [Egregor](https://attack.mitre.org/software/S0554).(Citation: Trend Micro Qakbot December 2020)(Citation: Red Canary Qbot)(Citation: Kaspersky QakBot September 2021)(Citation: ATT QakBot April 2021)

Platforms: Windows

▪Techniques implemented (71)

T1218.010Regsvr32T1564.001Hidden Files and DirectoriesT1497.001System ChecksT1018Remote System DiscoveryT1005Data from Local SystemT1090.002External ProxyT1059.001PowerShellT1059.003Windows Command ShellT1518.001Security Software DiscoveryT1106Native APIT1027.001Binary PaddingT1543.003Windows ServiceT1568.002Domain Generation AlgorithmsT1685Disable or Modify ToolsT1083File and Directory DiscoveryT1547.001Registry Run Keys / Startup FolderT1027.011Fileless StorageT1036.008Masquerade File TypeT1135Network Share DiscoveryT1055.012Process HollowingT1059.007JavaScriptT1218.007MsiexecT1140Deobfuscate/Decode Files or InformationT1114.001Local Email CollectionT1204.001Malicious LinkT1124System Time DiscoveryT1204.002Malicious FileT1041Exfiltration Over C2 ChannelT1033System Owner/User DiscoveryT1027.006HTML SmugglingT1016.001Internet Connection DiscoveryT1573.001Symmetric CryptographyT1027.010Command ObfuscationT1071.001Web ProtocolsT1553.002Code SigningT1027Obfuscated Files or InformationT1210Exploitation of Remote ServicesT1057Process DiscoveryT1069.001Local GroupsT1574.001DLLT1016System Network Configuration DiscoveryT1539Steal Web Session CookieT1055Process InjectionT1482Domain Trust DiscoveryT1074.001Local Data StagingT1110Brute ForceT1553.005Mark-of-the-Web BypassT1185Browser Session HijackingT1497.003Time Based ChecksT1105Ingress Tool TransferT1120Peripheral Device DiscoveryT1095Non-Application Layer ProtocolT1566.002Spearphishing LinkT1027.005Indicator Removal from ToolsT1112Modify RegistryT1566.001Spearphishing AttachmentT1056.001KeyloggingT1091Replication Through Removable MediaT1132.001Standard EncodingT1059.005Visual BasicT1082System Information DiscoveryT1047Windows Management InstrumentationT1010Application Window DiscoveryT1518Software DiscoveryT1049System Network Connections DiscoveryT1053.005Scheduled TaskT1218.011Rundll32T1572Protocol TunnelingT1555.003Credentials from Web BrowsersT1027.002Software PackingT1070.004File Deletion

▪Used by groups (3)

G0127TA551G1037TA577G1046Storm-1811
S0650on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.