Threat Intelligence Feed

S0650 - Qakbot

S0650 is the identifier for Qakbot, a banking Trojan that has been active since 2008. Qakbot is primarily used to steal sensitive financial information, such as banking credentials and credit card numbers, from victims’ computers. It is usually spread through spam emails, malicious attachments, or exploit kits.

Once installed on a victim’s computer, Qakbot can perform a wide range of malicious activities. It can steal login credentials and other sensitive information, such as social security numbers and email addresses. It can also download and install additional malware, modify system settings, and use the infected computer to launch further attacks on other systems.

Qakbot is particularly dangerous because it uses sophisticated techniques to avoid detection by antivirus software. It can encrypt its own code, hide its presence on the infected system, and use polymorphic techniques to generate new variants of itself that are difficult to detect.

To protect against Qakbot and other banking Trojans, users should be cautious when opening email attachments or clicking on links. They should also keep their operating system and software up to date, use antivirus software, and use strong, unique passwords for all online accounts.

In conclusion, S0650 – Qakbot is a dangerous banking Trojan that can steal sensitive financial information and perform a range of malicious activities. Users should take steps to protect themselves against this malware and other similar threats.