Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
    • Layer 2
  • Tech
    • Blockchain
    • Security and Privacy
    • Mining
  • Web 3
    • Web3 News
    • DeFi
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
What's Hot

ZKsync Era Delisted from DeFi Aggregator

21 June 2025

Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

21 June 2025

Stablecoin and Market Structure Bills Must Advance Together

21 June 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) LinkedIn
The Coin VibeThe Coin Vibe
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. Layer 2
    6. View All

    Bloomberg Analysts See 90% Chance SEC Clears Most Crypto ETFs Filings

    21 June 2025

    Norway Plans To Temporarily Ban New Bitcoin & Crypto Mining Centers To Conserve Energy

    21 June 2025

    Bitcoin’s price, miners, and THIS volatility indicator

    20 June 2025

    Government Bitcoin Holdings in 2025: Who Owns the Most?

    20 June 2025

    Ethereum – How changes in adoption stats and scarcity can fuel a new breakout

    21 June 2025

    Is ETH undervalued? Here’s why 15x stablecoin surge could benefit Ethereum!

    21 June 2025

    Trader Says Major Layer-One Altcoin Unlikely To Repeat 2024-Style Run, Updates Outlook on Bitcoin and Ethereum

    20 June 2025

    Ethereum Price Ready to Soar? $5B Liquidation at $2400 Says It All

    20 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025

    Company linked to Trump Family Slashes Equity Stake in World Liberty Financial Crypto Project

    21 June 2025

    SPX’s decrease of 11%: is this the calmness for a large rebound?

    20 June 2025

    Ton holds the line: Consolidation break can cause a new momentum

    20 June 2025

    Pump.fun’s $1B Token Auction Postponed Again to Mid-July

    20 June 2025

    Pump.fun Rebounds From Ban with Rumored $70M Fundraising

    19 June 2025

    Inside Pump.fun’s High-Stakes World of Winners and Losers

    19 June 2025

    PEPE Whale Sells at $3.5M Loss as 102% Rally Emerges

    18 June 2025

    Bubblemaps V2 goes live on Open Network

    19 June 2025

    Here’s why Polygon price is at risk of a 25% plunge

    18 June 2025

    Solana network extensions will redefine blockchain scaling

    17 June 2025

    L2s are leaking value, L1s are the smarter bet

    16 June 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. Mining
    4. View All

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Ostium Labs Hits $5B Milestone on Arbitrum, Leverages Chainlink for Speed and Security

    21 June 2025

    Magic Square.io Joins Metis HyperHack, Hackathon with $200K Prize Pool and AI-driven Web3 on Hyperion

    21 June 2025

    Exciting US Launch Prepares for RWA Tokenization Amidst Regulation Talks

    20 June 2025

    DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown

    21 June 2025

    Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware

    20 June 2025

    US Seizes $9m From Pig Butchering Scammers

    20 June 2025

    Rug Pull Schemes: Crypto Investor Losses Near $1M

    20 June 2025

    Bitcoin, Dogecoin Targeted as Norway Eyes Ban on New Crypto Mining Operations

    21 June 2025

    Norway plans temporary ban on power-intensive cryptocurrency mining

    20 June 2025

    Bitcoin’s Hashrate Nosedives After Weekend High—Miners Feel the Squeeze

    20 June 2025

    Only 30% of crypto miners comply with Russia’s new rules, finance ministry official says

    20 June 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025
  • Web 3
    1. Web3 News
    2. DeFi
    3. View All

    Regal Investments Commits $30 Million to Cryptocurrency Prop Trading Initiative

    21 June 2025

    How Mobile Apps Are Quietly Adopting Web3 Tech

    20 June 2025

    Detailed Plant Setup Report on Scanner Manufacturing Includes Business Plan, Layout and Cost Analysis

    20 June 2025

    Doodles NFT Sticker Launch on Telegram Sells Out in 24 Hours

    20 June 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Three Rules for Surviving DeFi Lending

    21 June 2025

    Quack AI Officially Collaborates with Coral Finance to Deliver AI-Led Governance

    21 June 2025

    Flamingo Finance launches THE FLOCK, sunsets FLM Hodlers program

    20 June 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Shares of Coinbase and Circle Explode in Value After US Senate Passes Landmark Stablecoin Bill

    21 June 2025

    App Store contains ‘crypto’ scams, lawsuit against Apple claims

    21 June 2025

    Philippines SEC lays down rules for crypto service providers

    21 June 2025

    KuCoin EU Appoints Banking Veteran Christian Derler And Legal Expert Tamara Rubey

    10 June 2025

    GameStop Drives Strategic Diversification With Staggering 4,710 $BTC Buyout

    28 May 2025

    Bybit Receives Clearance From French Regulator, Eyes MiCA License For Compliance Boost

    22 May 2025

    Bitget Secures VASP License In Bulgaria, Strengthening EU Expansion

    22 May 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025
  • Analysis

    Top US-Based Crypto Exchange by Trading Volume Coinbase Obtains MiCA License in Luxembourg, Moves European Hub

    21 June 2025

    Paolo Ardoino Says Tether Now Among the Top-20 Largest Holders of US Treasuries, Details Path to Taking US Dollar to 420,000,000 People

    20 June 2025

    How High Will XRP Price Go After Lawsuit?

    20 June 2025

    SEI Price Rebounds Sharply, Eyes $0.2545 as Next Target?

    20 June 2025

    Can BCH Break $600 and Go Higher?

    20 June 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    Crypto Portfolios That Thrive: Less Coins, More Conviction

    19 June 2025

    Crypto & Time: Building Wealth with Patience in a Hyper-Fast Market

    19 June 2025

    The Crypto Talent Shift: Why the Best Minds Are Leaving Silicon Valley for Blockchain

    18 June 2025

    Crypto and Time Perception: Why Digital Assets Distort Our Sense of Reality

    18 June 2025

    Binance Is Not Dumping SOL And ETH Through Wintermute

    23 May 2025

    US SEC Agency Drops Gemini & Tron ($TRX) Lawsuit

    23 May 2025

    Nischal Says Voting On The Wazirx Restructuring Scheme Will Start On 19 March

    22 May 2025

    Coinbase Secures Regulatory Approval To Resume Services In India

    22 May 2025

    ZKsync Era Delisted from DeFi Aggregator

    21 June 2025

    Luffa Partners with GlobalSync to Connect Decentralized Communication and Value Infrastructure

    21 June 2025

    Stablecoin and Market Structure Bills Must Advance Together

    21 June 2025

    Don’t miss your chance – how this presale ETH and Sol could surpass in the coming bull run

    21 June 2025
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
Subscribe
The Coin VibeThe Coin Vibe
Home»Security and Privacy»DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
Security and Privacy

DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown

21 June 2025No Comments5 Mins Read
Share Facebook Twitter LinkedIn
DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
Share
Facebook Twitter LinkedIn

Successors of the Qakbot malware arose despite the disruption of the Qakbot infrastructure due to an international law enforcement operation led by the FBI in August 2023.

Cofense, a provider of phishing detection solution, has observed new phishing campaigns that use the same infection tactics that would implement Qakbot. However, these recent campaigns deliver two new malware families, Darkgate and Pikabot.

One phishing campaign began to distribute Darkgate -Malware in September and has grown into one of the most advanced phishing campaigns active in the threat landscape, according to a report from Cofense. The campaign has evolved to use evasive tactics and anti-analysis techniques to continue to distribute Darkgate and, more recently, Pikabot.

Typical qakbot tactics observed in the Darkgate and Pikabot campaigns included:

  • Hijacked e -mailthreads as the first infection
  • URLs with unique patterns that limit user access
  • An infection chain that is almost identical to Qakbot delivery

Cofense researchers believe that some earlier Qakbot users have shifted to the use of Darkgate and/or Pikabot.

Some of these campaigns are undoubtedly a high -level threat[s] Because of the tactics, techniques and procedures (TTPs) with which the phishing -e -mails can achieve the intended goals, as well as the advanced possibilities of the malware that is supplied, “the report added.

Most campaigns after the Qakbot Takbot include different infection chains.

“Almost as if the threat actors were testing different malware delivery options,” said Cofense.

However, the most used infection chain shows many similarities with some Qakbot campaigns that were performed in May 2023.

“The campaign starts with a hijacked e -mailthread to ace to communicate with a URL that has added layers that only limit access to the malignant charge to users who meet specific requirements set by the threat factors (location and internet browser),” Cofense researchers outlined.

See also  Ethereum’s $2M Options Bet Fuels Hopes of Sharp Price Surge

“This URL downloads a ZIP archive that contains a JS file that is a JS -Dropper, a JavaScript application that is used to reach another URL to download and perform malware. In this stage a user is successfully infected with the Darkgate or Pikabot Malware.”

Some of these newly observed campaigns spread a large number of e -mails to a wide range of industries, which means that goals run the risk of more advanced threats such as reconnaissance malware and ransomware.

Read more: FBI-conducted Operation Duck Hunt shakes Qakbot Malware

What are the malware families from Darkgate and Pikabot?

Darkgate and Pikabot are both considered as advanced malware with characters and anti-analysis behavior.

Darkgate is a versatile malware tool set, usually distributed via spam -e -mail attachments or malignant links, which has been active since 2017. It is equipped with various options, including data stems, cryptocurrency -mining and remote control of infected systems.

Once installed, DarkGate can steal a variety of sensitive information, including passwords, credit card numbers and personal documents. It can also be mine for cryptocurrency, which can use the victim’s computer sources to generate money for the attackers.

In addition, DarkGate can enable attackers to drive the infected system remotely, which can be used to install other malware, steal data or start attacking on other systems.

Pikabot is a new malware family for the first time observed in 2023. It is classified as a charger because of its ability to deliver extra malware -payloads. It contains various evasive techniques to prevent sandboxes, virtual machines and other error detection techniques.

See also  High-profile X Accounts Targeted in Phishing Campaign

Pikabot is usually spread by phishing attacks or by exploiting vulnerabilities in software. Once installed, Pikabot can be driven remotely by attackers.

It has been observed that the infectious machines excludes the Commonwealth of the countries of Independent States (CIS) – all members of the former Soviet Union.

How is the infrastructure of Qakbot brought down?

In August, the FBI Operation Duck Hunt led a multinational law enforcement operation that reportedly dismantled Qakbot.

To do this, the FBI gained access to the managers of Qakbot, who helped the law enforcement instruction when mapping the server infrastructure used in the operation of the botnet. Then it seized 52 servers, of which it would permanently ‘dismantle’ the Botnet and the traffic of Qakbot would be forwarded by the desk by the desk, so that victims can download a removal capacity.

In an additional announcement, the US Department of Justice (DOJ) said that the FBI had identified more than 700,000 infected computers worldwide, including more than 200,000 in the US.

The DOJ also announced that it took more than $ 8.6 million in the Cryptocurrency of the Qakbot Cybercriminal Organization. This money is returned to the victims.

While the cyber security community has generally praised Operation Duck Hunt, the voices doubted the actual impact of the Takedown.

The possibility that threat actors would move to use other malware families to use the same type of malignant campaigns was one of the criticism of the effectiveness of such an operation.

Read more: FBI’s Qakbot Takedown raises questions: ‘Dischaired’ or just a temporary setback?

Activity DarkGate PikaBot QakBot surge Takedown Wake
Follow on X (Twitter)
Share. Facebook Twitter LinkedIn
Previous ArticleThree Rules for Surviving DeFi Lending
Next Article Ethereum – How changes in adoption stats and scarcity can fuel a new breakout

Related Posts

Ethereum

Is ETH undervalued? Here’s why 15x stablecoin surge could benefit Ethereum!

21 June 2025
Security and Privacy

Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware

20 June 2025
Legal and Regulatory

Unlicensed Crypto Activity in Jordan Could Soon Carry Jail Time

20 June 2025
Add A Comment
Leave A Reply Cancel Reply

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Posts
Analysis

Stellar (XLM) Price Analysis: Is a Run to $0.38 on the Horizon?

2 June 2025
Bitcoin

Trump tariffs crash stocks – But Bitcoin has seen it all before

24 May 2025
Top Posts

Can Solana Break the $180 Resistance? Here’s What SOL Price Will Be Worth in 2025!

24 May 2025128 Views

Trump Family Backed American Bitcoin To Go Public via Merger With Gryphon Digital

20 May 202516 Views

Wazirx’s Nischal Shetty Reports $478.5m Net Liquid Assets As Voting Starts

20 May 202512 Views

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest
Top Insights

Senator Lummis Pushes Crypto Tax Crackdown in GOP Bill

7 June 2025

SHIB Whale Inflows Crash 83% as Burn Rate Spikes 12,715%

27 May 2025

XRP Gets Another DeFi Boost Through Flare’s FAssets and FXRP, Messari Says

17 June 2025
Get Informed

Subscribe to Updates

Spice Up Your Crypto Knowledge – Get the Latest News & Insights Straight to Your Inbox!

Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 thecoinvibe.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.