MALLARD SPIDER
Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
MALLARD SPIDER is the threat actor behind Qbot malware, targeting the financial sector for initial access.
MALLARD SPIDER (also tracked as GOLD LAGOON) is the threat actor behind the Qbot (Qakbot) malware, as identified by CrowdStrike. This actor primarily targets financial and insurance sectors to gain initial access. Their key TTPs involve distributing the Qbot payload via spear-phishing emails, followed by establishing C2 communications for data theft and selling access to ransomware operators. Defenders should focus on email security gateways, monitoring for suspicious macro executions, and blocking known Qbot-related IOCs.
Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
MALLARD SPIDER operates the Qbot (also known as Qakbot) malware.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.