Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Blockchain won’t win until it outruns TradFi

July 27, 2025

Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

July 27, 2025

Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

July 27, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Bitcoin Primed for New All-Time High After Correction, According to Trader Who Nailed 2018 BTC Bottom – Here’s His Target

    July 27, 2025

    Crypto Still Seen as 'Risky' Among U.S. Investors Despite Ownership Surging 8x Since 2018: Survey

    July 27, 2025

    Ancient Bitcoin (BTC) Springing to Life, Signaling Potential Sell-Side Pressure: Crypto Analytics Firm

    July 26, 2025

    HBAR Surges 12% Following Robinhood Listing, Making it Top Daily Gainer Among Top 20

    July 26, 2025

    Crypto Founder Reveals What Will Drive Ethereum Price To $10,000

    July 27, 2025

    Ethereum ETFs see $1.85B inflows – 25x more than Bitcoin!

    July 27, 2025

    Ethereum Price Gains 75%: What’s Fueling the Rally?

    July 26, 2025

    Billionaire Mike Novogratz Says Ethereum Will Enter Price Discovery If It Takes Out This Level

    July 26, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025

    Bitcoin Price Could Still Tumble Down To $109,000 — This Chart Pattern Suggests So

    July 27, 2025

    Bitcoin DeFi grows 20x – Is BTC becoming the next yield powerhouse?

    July 27, 2025

    El Salvador’s Bitcoin Strategy Faces Doubts Amid IMF Pressure and Mixed Signals

    July 26, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025
  • DeFi

    Injective launches SBET, the first onchain Digital Asset Treasury

    July 27, 2025

    US TikTok influencer helped North Korean operatives land jobs at 300 Companies: DOJ

    July 27, 2025

    Kraken to integrate INK token and L2 to power onchain expansion

    July 26, 2025

    EU BTC treasuries pile up as Refine Group raises $475k to buy Bitcoin

    July 26, 2025

    Why is Ethena up 20% today?

    July 26, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Hacken Report Flags $3.1B Web3 Meltdown, 1,025% Spike in AI Attacks

    July 27, 2025

    A Game-Changer for Network Efficiency

    July 27, 2025

    Crypto Council For Innovation Names Ji Hun Kim As CEO After Sheila Warren Departure

    July 27, 2025

    Active Campaign Exploits Cloud Flaws for Cryptomining

    July 24, 2025

    Accounting Firm Targeted by Malware Campaign Using New Crypter

    July 22, 2025

    Grok refuses to pick winner for Crypto Rover competition citing ZachXBT pump and dump evidence

    July 21, 2025

    XRP trading volume soars as new ATH attracts deepfake scam targeting investors

    July 18, 2025

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Adoption of Advanced Biometric Solutions in Poland Market 2021 to 2038

    July 27, 2025

    This single point of failure can kill web3’s dream of an open, decentralized internet

    July 27, 2025

    Remote Control Kits Market Sees Surge with IoT and AI Integration

    July 26, 2025

    Off the Grid Skin Sale Volume Hits $30K as the Avalanche Shooter Hits OpenSea

    July 26, 2025

    Octo Gaming Teams Up with Starknet for Exclusive Rollup-Powered Game Launch

    July 25, 2025

    $NAKA’s Play‑to‑Earn Ecosystem Explained: Games, Catalysts, and Where It’s Headed

    July 25, 2025

    Axie Infinity Creator Sky Mavis Backs New BORA-Integrated Game on LINE NEXT App

    July 25, 2025

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    FBI Drops Criminal Probe Into Kraken Founder Jesse Powell

    July 27, 2025

    South Korea’s Ruling Party Pushes to Speed Up Bitcoin Laws After U.S. Genius Act

    July 26, 2025

    The Senate Must Finish the Job on America’s Pro-Crypto Future—Emmer, Begich

    July 26, 2025

    The coming Bitcoin treasury bubble could rival the dot-com era with $11T of capital chasing BTC

    July 27, 2025

    Robert Kiyosaki slams ETFs for being ‘paper versions’ of Bitcoin, gold and silver

    July 26, 2025

    public firms holding at least 1,000 BTC grow 50% in 2025 – Fidelity

    July 26, 2025

    Bitcoin’s evolving market dynamics signal end of four-year cycle predictions

    July 25, 2025

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025
  • Analysis

    XRP, Sui, and Pudgy Penguins Set to Hit New All-Time Highs Next Week: Top Altcoins to Watch

    July 27, 2025

    Arthur Hayes-Backed Altcoin Outpaces Crypto Market Amid Launch of New Partnership With Anchorage Digital

    July 26, 2025

    Ethena Price Rockets 20%, Can ENA Hit $1 Amid StablecoinX’s Buyback?

    July 26, 2025

    Two Solana (SOL)-Based Altcoins Get the Nod From Top US-Based Crypto Exchange by Trading Volume Coinbase

    July 26, 2025

    Bullish And Bearish Scenarios Explained

    July 25, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Tokenization?

    July 11, 2025

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    MEXC finds that 67% of Gen Z crypto traders use AI tools, resulting in fewer panic sells

    July 26, 2025

    Ancient whale sells $8 billion Bitcoin via Galaxy as price dips to $115k

    July 26, 2025

    WOO X suffers $14 million breach affecting 9 users, halts withdrawals

    July 25, 2025

    FTX creditors to receive next round of payouts by Sept 30

    July 24, 2025

    Blockchain won’t win until it outruns TradFi

    July 27, 2025

    Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

    July 27, 2025

    Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

    July 27, 2025

    Futures fuel Ethereum’s rally to $3.5K: But overheating indicators raise alarm

    July 27, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
Security and Privacy

DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown

December 21, 2024No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Successors to the QakBot malware have emerged despite the disruption to QakBot infrastructure by an international law enforcement operation led by the FBI in August 2023.

Cofense, a phishing detection solution provider, has observed new phishing campaigns that use the same infection tactics QakBot was known to deploy. However, these recent campaigns deliver two new malware families, DarkGate and PikaBot.

One phishing campaign began spreading DarkGate malware in September and has grown to become one of the most advanced phishing campaigns active in the threat landscape, according to a report by Cofense. The campaign has evolved to use evasive tactics and anti-analysis techniques to continue distributing DarkGate and, more recently, PikaBot.

Typical QakBot tactics observed in the DarkGate and PikaBot campaigns included:

– Hijacked email threads as the initial infection
– URLs with unique patterns that limit user access
– An infection chain nearly identical to QakBot delivery

Cofense researchers believe that some previous QakBot users have shifted to using DarkGate and/or PikaBot.

Some of these campaigns are “undoubtedly high-level threat[s] due to the tactics, techniques, and procedures (TTPs) that enable the phishing emails to reach intended targets as well as the advanced capabilities of the malware being delivered,” added the report.

Most of the post-QakBot takedown campaigns involve different infection chains.

“Almost as if the threat actors were testing different malware delivery options,” Cofense said.

However, the most used infection chain shows many similarities with some QakBot campaigns conducted in May 2023.

“The campaign begins with a hijacked email thread to bait users into interacting with a URL that has added layers that limit access to the malicious payload only to users that meet specific requirements set by the threat actors (location and internet browser),” outlined Cofense researchers.

See also  Metaplanet to launch Bitcoin Magazine in Japan amid BTC surge

“This URL downloads a ZIP archive that contains a JS file that is a JS Dropper, which is a JavaScript application used to reach out to another URL to download and run malware. At this stage, a user has been successfully infected with either the DarkGate or PikaBot malware.”

Some of these newly observed campaigns disseminated a high volume of emails to a wide range of industries, putting targets at risk of more sophisticated threats like reconnaissance malware and ransomware.

What are the DarkGate and PikaBot Malware Families?

DarkGate and PikaBot are both considered advanced malware with loader capabilities and anti-analysis behavior.

DarkGate is a versatile malware toolset, typically spread through spam email attachments or malicious links, that has been active since 2017. It is equipped with various capabilities, including data stealing, cryptocurrency mining and remote control of infected systems. Once installed, DarkGate can steal a variety of sensitive information, including passwords, credit card numbers and personal documents. It can also mine for cryptocurrency, which can use the victim’s computer resources to generate money for the attackers.

In addition, DarkGate can allow attackers to remotely control the infected system, which could be used to install other malware, steal data or launch attacks against other systems.

PikaBot is a new malware family first observed in 2023. It is classified as a loader due to its ability to deliver additional malware payloads. It contains several evasive techniques to avoid sandboxes, virtual machines and other debugging techniques. PikaBot is typically spread through phishing attacks or by exploiting vulnerabilities in software. Once installed, PikaBot can be controlled by attackers remotely. It has been observed to exclude infecting machines in Commonwealth of Independent States (CIS) countries – all members of the former Soviet Union.

See also  Top 10: Cryptocurrency Heists - Infosecurity Magazine

How Was QakBot’s Infrastructure Taken Down?

In August, the FBI led Operation Duck Hunt, a multinational law enforcement operation that allegedly dismantled QakBot. To do this, the FBI gained access to QakBot’s admin computers, which helped law enforcement map out the server infrastructure used in the botnet’s operation. It then seized 52 servers, which it said would “permanently dismantle” the botnet, and redirected QakBot’s traffic to servers controlled by the Bureau, pointing victims to download an uninstaller.

In an additional announcement, the US Department of Justice (DoJ) said the FBI had identified over 700,000 infected computers worldwide, including more than 200,000 in the US. The DoJ also announced it seized over $8.6m in cryptocurrency from the QakBot cybercriminal organization. This money will be returned to the victims.

While the cybersecurity community has generally praised Operation Duck Hunt, voices doubted the real impact of the takedown. The possibility that threat actors would be moving to use other malware families to deploy the same type of malicious campaigns was one of the criticisms about the efficacy of such an operation.

Activity DarkGate PikaBot QakBot surge Takedown Wake
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Remote Control Kits Market Sees Surge with IoT and AI Integration

July 26, 2025

Matrixport Flags Summer Consolidation After Crypto Week Surge

July 25, 2025

Active Campaign Exploits Cloud Flaws for Cryptomining

July 24, 2025

Ozzy Osbourne’s NFT Collection Sees Price Surge After Rock Icon’s Death

July 24, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Linera and Dojima Partner to Advance Real-Time Omnichain Web3 Apps

April 4, 2025

Bitcoin Price Finally Approaches $100K After Almost 100 Days, New ATHS Soon?

May 8, 2025

How Bitcoin Will Benefit from Trump’s Pro-Crypto Agenda After Jan 2025

January 6, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Blockchain won’t win until it outruns TradFi

July 27, 2025

Is Ripple Powering BlackRock’s $100 Trillion Blockchain Vision?

July 27, 2025

Ex-Gemini, Kraken exec appointed as CEO of crypto advocacy group

July 27, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.