<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys" -->

---
title: QakBot Threat Actors Still in Action, Using Ransom...
description: Threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight...
canonical: https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks | daily.dev
og:description: Threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight...
og:url: https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys
og:image: https://api.daily.dev/og/posts/nUJ7WrcYS.png
og:image:alt: QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

**[The Hacker News](https://daily.dev/sources/thn)** · 2 min read · 0 upvotes · 0 comments

## Summary

Threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight ransomware and Remcos RAT. Despite infrastructure disruption, the threat actors continue their activity, indicating that their command-and-control servers were impacted but not their spam delivery infrastructure.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2023/10/qakbot-threat-actors-still-in-action.html>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing), [#qakbot](https://daily.dev/tags/qakbot), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks","url":"https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys"},"datePublished":"2023-10-05T13:44:28.983Z","dateModified":"2024-01-27T02:16:08.441Z","description":"Threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f231f81333b11351236e97d9f5715371?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f231f81333b11351236e97d9f5715371?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"The Hacker News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Hacker News","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/thn","url":"https://daily.dev/sources/thn"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/qakbot-threat-actors-still-in-action-using-ransom-knight-and-remcos-rat-in-latest-attacks-nuj7wrcys","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,phishing,qakbot,ransomware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Hacker News","item":"https://daily.dev/sources/thn"},{"@type":"ListItem","position":3,"name":"QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks"}]}
```

