Malware

QakBot (QBot) explained: banking Trojan, loader and safe response

What is QakBot or QBot? Learn its aliases, banking-Trojan history, loader role, the August 2023 disruption, and safe alert-response steps.

Original conceptual illustration showing qakbot banking trojan, loader and 2023 disruption without embedded text or logos

QakBot, also called QBot, QuackBot and Pinkslipbot, is Windows malware that began as a banking Trojan and later became a modular loader and botnet component. It was used to steal credentials and other information, provide remote access, and deliver additional malware, including ransomware. It is not a file-infecting computer virus in the strict sense. The most important date in its public record is August 2023. On August 25, the FBI and international partners carried out a coordinated operation against QakBot infrastructure; the U.S. Department of Justice announced the operation on August 29, 2023, and CISA and the FBI published a joint advisory on August 30, 2023. That operation disrupted the botnet and used a law-enforcement-controlled process to remove QakBot from identified infected computers. It did not prove that every affected computer was clean, and it did not remove other malware already installed.

What is QakBot or QBot?

MITRE ATT&CK tracks QakBot as S0650, a modular banking Trojan used by financially motivated actors since at least 2007. CISA and the FBI describe it as existing since at least 2008 and say its original purpose was stealing banking credentials. Those different “at least” dates reflect different records and should not be treated as a precise discovery date.

QakBot operated as more than a single credential-stealing program. Its modular design allowed operators or affiliates to add capabilities such as reconnaissance, credential theft, data collection and exfiltration, persistence, command-and-control communication, and delivery of follow-on payloads. In the public record, QakBot infections preceded deployments associated with several ransomware families. That makes “loader” a useful description of its later role, while “banking Trojan” remains important to its history and core identity.

Is QakBot a virus?

No—not in the narrow technical meaning of virus. A file-infecting virus attaches itself to or modifies other files and spreads when those files are executed. QakBot is better classified as a Trojan and botnet malware family: it is delivered deceptively, compromises a host, communicates with criminal infrastructure, and can receive modules or payloads.

People may still search for “QakBot virus” because everyday language uses virus for malware in general. A precise explanation should keep the terms separate. QakBot can spread through phishing campaigns and may help attackers move through an environment, but that does not make it a self-replicating file virus.

For a broader distinction between malware families, see CYBERoinfo’s Trojan malware explainer and botnet explainer. Those pages explain the categories; this page owns the QakBot/QBot identity and history.

Which names refer to the same malware?

The names below are aliases or associated labels in the cited records, not separate CYBERoinfo page topics:

Security products may use family names such as Qakbot, Qbot, or a vendor-specific detection suffix. The name alone is not enough to confirm which component ran, when it ran, or whether follow-on malware is present.

  • QakBot — the primary MITRE ATT&CK label and the spelling used by CISA and the FBI.
  • QBot — a common security-product and research label.
  • QuackBot — an associated spelling listed by CISA and MITRE.
  • Pinkslipbot or Pinkslipbot — an associated name used in government and ATT&CK records.
  • TA570 — included by CISA among associated labels, but this label can also refer to a threat-actor or affiliate designation in other reporting. It should not automatically be treated as a malware alias.

How did QakBot work as a banking Trojan and loader?

Historically, QakBot was delivered mainly through phishing email containing a malicious attachment or link. A user action could give the malware an initial foothold. CISA and the FBI describe QakBot as a Windows threat that could reside in memory in many infection scenarios and use a modular design to add functionality.

Its documented roles included:

These are capabilities documented in historical technical records, not a claim that every QakBot sample or every alert used every capability.

  • Credential and information theft: collecting banking credentials and other account or system information, including through browser or web-injection activity described in ATT&CK’s supporting references.
  • Botnet participation: turning compromised Windows computers into remotely controlled nodes that communicated through layered command-and-control infrastructure.
  • Environment discovery and movement: gathering information about the host or network and, in documented campaigns, supporting activity against additional systems.
  • Payload delivery: downloading or enabling other malware, including tools and ransomware used by separate criminal operators.
  • Persistence and evasion: using mechanisms such as Registry Run keys and checks intended to make analysis or detection harder, as recorded in ATT&CK’s technique mappings.

What happened in the August 2023 QakBot disruption?

The public record supports a specific, qualified account:

The operation redirected QakBot traffic through servers controlled by the FBI. An uninstall file was sent to identified infected computers to remove QakBot and detach those computers from the botnet. DOJ and CISA both warned that this action did not remediate other malware or ransomware already on a computer.

This was a major disruption, not evidence that all QakBot-related criminal activity was permanently eradicated. It is also not evidence of a fresh 2026 surge. This page makes no current-activity claim without a current, attributable source.

  • August 25, 2023: the FBI and international partners executed a coordinated operation against QakBot infrastructure, according to the CISA-FBI advisory.
  • August 29, 2023: the DOJ and FBI announced the multinational disruption. DOJ said investigators identified more than 700,000 computers that appeared to have been infected, including more than 200,000 in the United States. Those are government-reported figures for the operation, not a current prevalence estimate.
  • August 30, 2023: CISA and the FBI published advisory AA23-242A with indicators and response guidance.

What should I do if a security tool reports QakBot?

Treat the alert as a possible compromise and verify it through trusted security or incident-response channels. Do not try to obtain, execute or reverse-engineer a sample on a personal or production computer.

Question: Practical checklist for a personal device

Question: Practical checklist for an organization

  • Stop using the device for banking, shopping and sensitive accounts. Use a separate, trusted device to contact your bank or payment provider if financial activity may be exposed.
  • Disconnect the suspected Windows device from networks if you can do so safely, without destroying information that an incident responder may need.
  • Record the alert details: product name, detection time, device name, user, and any account or transaction concerns. Do not rely on a screenshot as the only record.
  • Contact the organization’s IT or security team if the device is managed. For an unmanaged device, use a reputable support or incident-response provider and the operating system vendor’s supported security tools.
  • Change exposed passwords from a clean device, prioritizing email, financial, administrator and recovery accounts. Revoke active sessions or tokens where the service supports it, and enable multifactor authentication.
  • Check bank and email activity for unauthorized changes, forwarding rules, new payees, password resets or unfamiliar sign-ins. Report suspected fraud through the institution’s official channel.
  • Do not assume that removing the QakBot detection proves the device is clean. Ask whether the device needs a supported rebuild or additional investigation for other malware.
  • Isolate the endpoint according to the organization’s incident-response plan.
  • Preserve relevant endpoint, email, identity, DNS, proxy and authentication logs before routine retention removes them.
  • Search for related activity across other Windows hosts and accounts, not only the machine that raised the alert.
  • Review whether credentials, browser sessions, email accounts or privileged access may have been exposed; reset or revoke them from trusted systems.
  • Check for follow-on malware, unauthorized remote access, lateral movement and ransomware indicators.
  • Coordinate containment, eradication and recovery with qualified responders. Report material incidents through the appropriate national or sector channel.

Can an old QakBot alert prove a current infection?

No. A detection may refer to a historical file, a blocked email, a quarantine record, a stale artifact, a false positive, or a genuinely active compromise. The detection name, timestamp, file path, process context and network evidence matter. A 2023 law-enforcement cleanup also cannot establish the current state of a device in 2026.

Likewise, QakBot’s presence in MITRE ATT&CK documents its known identity and techniques; it does not measure current prevalence, active campaigns or search demand. Claims such as “QakBot is back,” “QakBot is gone everywhere,” or “QakBot is the most dangerous malware” require current, attributable evidence and a defined measurement method.

What is the safe takeaway?

QakBot is best understood as a banking Trojan that evolved into a modular loader and botnet service, not as a generic computer virus. The August 2023 operation disrupted documented infrastructure and removed QakBot from identified computers in the law-enforcement process, but it was not a universal cleanup. If an alert appears, protect accounts, isolate and investigate the affected system, and look for other malware rather than relying on the family name alone.

Evidence limits and editorial note

This article relies on MITRE ATT&CK S0650, the DOJ and FBI accounts of the August 2023 operation, and the joint CISA-FBI advisory. The sources use different “at least” dates for QakBot’s early history and describe capabilities across versions and campaigns. Counts reported by DOJ are historical operation figures, not current infection totals. No current 2026 QakBot surge, eradication claim, ranking promise or universal remediation claim is made here.

Decision checklist

  • Stop using the device for banking, shopping and sensitive accounts. Use a separate, trusted device to contact your bank or payment provider if financial activity may be exposed.
  • Disconnect the suspected Windows device from networks if you can do so safely, without destroying information that an incident responder may need.
  • Record the alert details: product name, detection time, device name, user, and any account or transaction concerns. Do not rely on a screenshot as the only record.
  • Contact the organization’s IT or security team if the device is managed. For an unmanaged device, use a reputable support or incident-response provider and the operating system vendor’s supported security tools.
  • Change exposed passwords from a clean device, prioritizing email, financial, administrator and recovery accounts. Revoke active sessions or tokens where the service supports it, and enable multifactor authentication.
  • Check bank and email activity for unauthorized changes, forwarding rules, new payees, password resets or unfamiliar sign-ins. Report suspected fraud through the institution’s official channel.
  • Do not assume that removing the QakBot detection proves the device is clean. Ask whether the device needs a supported rebuild or additional investigation for other malware.
  • Isolate the endpoint according to the organization’s incident-response plan.
  • Preserve relevant endpoint, email, identity, DNS, proxy and authentication logs before routine retention removes them.
  • Search for related activity across other Windows hosts and accounts, not only the machine that raised the alert.

Limitations

  • An alert or family name alone does not confirm an infection or data theft on a particular device.
  • Historical activity and vendor capability descriptions are not proof of a present-day outbreak or specific sample behavior.
  • A scan or infrastructure disruption cannot guarantee that every related threat was removed.
  • This educational article is not personalized incident-response or a device-specific diagnosis.

Evidence sources

  1. MITRE ATT&CK — MITRE ATT&CK, QakBot (S0650)
  2. U.S. Department of Justice — Qakbot Malware Disrupted in International Cyber Takedown
  3. CISA — Identification and Disruption of QakBot Infrastructure
  4. FBI — FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown
  5. U.S. Department of Justice — Resources for Victims of the Qakbot Malware
  6. CISA — Malware Analysis