Malware · high

How to fixQAKBOT_STEALER_BACKDOOR

Qbot / Qakbot Info-Stealer & Backdoor

What this error means

Qbot / Qakbot Info-Stealer & Backdoor (QAKBOT_STEALER_BACKDOOR) is a high-severity fault affecting the malware/security. Qakbot (or Qbot) is a long-standing information-stealing Trojan and backdoor. It captures banking credentials, keystrokes, and emails, and acts as an entry point for ransomware gangs to deploy larger payloads like Black Basta. Common triggers are drive-by downloads on compromised web pages and lateral movement via SMB share exploits. Follow the steps below to fix it.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Perform a full offline malware scan and clean the registry startup paths

Perform a full offline malware scan and clean the registry startup paths.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Block outbound connections to known C2 server IP addresses

Block outbound connections to known C2 server IP addresses.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Enforce strict email gateway attachments filters

Enforce strict email gateway attachments filters.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Reset all compromised account credentials

Reset all compromised account credentials.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Phishing emails with malicious OneNote files, PDFs, or ZIP archives
  • Drive-by downloads on compromised web pages
  • Lateral movement via SMB share exploits