Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

QakBot

Ransomware Needs review 35 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog because it self-identifies as ransomware-type malware, but no one has curated a full summary or double-checked its reference links. Treat the details below as a starting point, not a verified profile.

Also known as: Pinkslipbot, QBot, QakBot, QuackBot

Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0650) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
splunk Windows App Layer Protocol Wermgr Connect To NamedPipe production 2026-08-18
splunk Windows Process Injection Wermgr Child Process production 2026-08-18
splunk Windows Process Injection Remote Thread production 2026-08-14
splunk Windows Uncommon Remote Thread Creation In Browser Process production 2026-06-29
splunk Windows System Discovery Using ldap Nslookup production 2026-05-13
splunk Windows System Discovery Using Qwinsta production 2026-05-13
splunk Windows App Layer Protocol Qakbot NamedPipe production 2026-05-13
splunk Windows DLL Side-Loading In Calc production 2026-05-13
splunk Windows DLL Side-Loading Process Child Of Calc production 2026-05-13
splunk Windows List ENV Variables Via SET Command From Uncommon Parent production 2026-05-13
splunk Windows Masquerading Explorer As Child Process production 2026-05-13
splunk Windows Modify Registry Qakbot Binary Data Registry production 2026-05-13
splunk Windows MsiExec HideWindow Rundll32 Execution production 2026-05-13
splunk Windows Process Injection In Non-Service SearchIndexer production 2026-05-13
suricata ET MALWARE W32/Qakbot.Bot Version 8 CnC Beacon rev 6 2024-04-30
sigma Qakbot Regsvr32 Calc Pattern test 2024-03-05
sigma Esentutl Steals Browser Information test 2024-03-05
sigma Cscript/Wscript Potentially Suspicious Child Process test 2024-01-02
sigma Qakbot Uninstaller Execution test 2023-09-01
sigma Qakbot Rundll32 Exports Execution test 2023-05-30
sigma Qakbot Rundll32 Fake DLL Extension Execution test 2023-05-24
sigma Potential Qakbot Rundll32 Execution test 2023-05-24
sigma Potential Qakbot Registry Activity test 2023-03-13
sigma Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE test 2023-02-04
sigma Potential QBot Activity stable 2023-02-03
sigma ISO File Created Within Temp Folders test 2022-07-30
suricata ET USER_AGENTS Possible QBot User-Agent rev 1 2020-05-11
snort ET USER_AGENTS Possible QBot User-Agent rev 2 2020-05-11
suricata ET MALWARE W32.Qakbot Webpage Infection Routine POST rev 4 2020-04-21
suricata ET MALWARE W32.Qakbot Request for Compromised FTP Sites rev 3 2020-04-20
suricata ET MALWARE Win32/Qbot/Quakbot Downloader - Requesting Secondary Download rev 2 2020-02-28
snort ET TROJAN Win32/Qbot/Quakbot Downloader - Requesting Secondary Download rev 2 2020-02-28
snort ET TROJAN W32/Qakbot.Bot Version 8 CnC Beacon rev 2 2014-03-04
snort ET TROJAN W32.Qakbot Webpage Infection Routine POST rev 2 2012-03-20
snort ET TROJAN W32.Qakbot Request for Compromised FTP Sites rev 1 2011-06-09