Qakbot malware returns, despite the FBI saying it took it out
The FBI’s mission against the dreaded Qakbot malware operators might not have been as successful as initially thought, as in true comic book fashion, the cyber-villains are back with a vengeance.
Cybersecurity researchers from Cisco Talos recently released a new report stating that QakBot operators are likely behind a brand new phishing campaign (active since August this year), whose goal is to deliver the Cyclops and Remcos RATs (remote access trojan).
“The law enforcement operation may not have impacted Qakbot operators’ spam delivery infrastructure but rather only their command and control (C2) servers,” the report reads.
Operation Duck Hunt
The news follows an announcement in late August 2023 from FBI Director Christoper Wray, who spoke about taking down one of the biggest and most disruptive botnet malicious networks around in its Operation Duck Hunt.
“The victims ranged from financial institutions on the East Coast to a critical infrastructure government contractor in the Midwest to a medical device manufacturer on the West Coast,” Wray said in the video. “This botnet provided cybercriminals like these with a command-and-control infrastructure consisting of hundreds of thousands of computers used to carry out attacks against individuals and businesses all around the globe.”
While Talos’ researchers link the campaign with QakBot affiliates, they did stress that they’ve been distributing other RATs, rather than the QakBot loader itself. “Though we have not seen the threat actors distributing Qakbot post-infrastructure takedown, we assess the malware will likely continue to pose a significant threat moving forward,” Venere said.
“We see this as likely as the developers were not arrested and are still operational, opening the possibility that they may choose to rebuild the Qakbot infrastructure.”
QakBot is a piece of malware more than a decade old, sometimes also known as Qbot, or Pinkslipbot. It targets Windows-powered endpoints, and has evolved heavily through the years to, among other things, deliver ransomware, as well.
More from TechRadar Pro
The FBI’s mission against the dreaded Qakbot malware operators might not have been as successful as initially thought, as in true comic book fashion, the cyber-villains are back with a vengeance. Cybersecurity researchers from Cisco Talos recently released a new report stating that QakBot operators are likely behind a brand…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023