Like a zombie, Qakbot’s back.

Share This Post

In a not-so-unexpected turn of events, Qakbot is back. Just a short time after the August takedown of the notorious group, researches have found that these threat-actors are still active. In fact, they may have never actually been inactive, as an attack campaign that was active DURING the takedown, is still active.

The current campaign involves two primary pieces of malware:

  • Ransom Knight – a Ransomware as a Service malware being delivered via .lnk files that are set to download this malware upon execution.
  • Remcos backdoor – a remote access trojan allowing persistent access for further attacks even after ransomware has been deployed.

As always, the best defense against Qakbot attacks is education. Qakbot is primarily delivered via email attachments, and users should be made aware of this and educated on how to handle these emails. Additionally, Qakbot is exceptionally evasive and persistent. Any indication that it may have been unleashed on your network requires prompt, diligent and thorough threat-hunting and eradication.

For more more information on Qakbot’s Halloween-appropriate undead act see this article: https://www.darkreading.com/attacks-breaches/qakbot-infections-continue-even-after-high-profile-raid



Reach out to our incident response team for help

More To Explore

Information Security News – 2/2/2026

FBI Seizes RAMP Cybercrime Forum Used by Ransomware Gangs Article Link: https://www.bleepingcomputer.com/news/security/fbi-seizes-ramp-cybercrime-forum-used-by-ransomware-gangs/ U.S. Charges 31 Suspects in Nationwide ATM Jackpotting Scam Article Link: https://hackread.com/us-charges-atm-jackpotting-scam-suspects/ Nike

Information Security News – 1/26/2026

The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time Article Link: https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/ NIST, MITRE Announce $20 million Research

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.