QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.56
tool
QakBot S0650
- Type
- malware
- Platform
- Windows
- Created
- 27 September 2021
- Last modified
- 17 November 2024
QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0650
QakBot has the ability to enumerate windows on a compromised host.7
QakBot can use net config workstation, arp -a, nslookup, and ipconfig /all to gather network configuration information.89101112
QakBot can identify remote systems through the net view command.141516
QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.17
Standing S0650
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
100th percentile · None of the 825 ATT&CK software entries has more Enterprise techniques — the highest in the population.
100th percentile · None of the 825 ATT&CK software entries has more tactics spanned — the highest in the population.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0650
2125 distinct rules cover the 71 techniques recorded for this tool. The 2549 technique-to-rule mappings resolve to 2125 distinct rules, because one rule can cover several techniques. 1388 Sigma · 737 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org