Navigation and service

Qakbot

Name of Malware: Qakbot (Qbot, Pinkslipbot)

warning triangle red

Type of Malware: trojan, banking trojan, downloader

Affected Operating Systems: Windows

Affected Device Types: PCs, laptops, etc.

Impact: high

What is Qakbot?

Qakbot is a Trojan for Windows devices.

Its main functions are spying out the data of the person concerned, manipulating online banking and loading and installing further malware. Ransomware is used for encrypting the computer system with the aim of blackmailing the victim.

How did I get infected with Qakbot?

Opening malicious email attachments can infect systems with Qakbot. The malware is contained in a file that appears to be benign. The attachments often have names such as invoice, reminder or similar to tempt the user to act carelessly.

Alternatively, links to websites hacked by criminals can appear instead of attachments. Attackers hide malicious scripts on these websites. These scripts are used to download and install the malware without the victims' consent.

What do I have to do now?

In order to eliminate Qakbot and, if necessary, detect further infections, it is recommended to scan the infected system with an antivirus program and remove any hits.

Further information on removing this malware can be found under Removing infections from PCs, laptops etc.

Technical specifications

Further information on this malware can be found on the website of our project partner Fraunhofer FKIE.