Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

U.S. CFTC in talks with every major pro sports league on policing prediction markets

May 14, 2026

Monad Backs Stablecoin Startup Rain for Global Visa Payments

May 14, 2026

Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

May 14, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    ZachXBT Names Teen Behind $19 Million Crypto Theft Who Flaunted It On Instagram

    May 14, 2026

    Analyst Says No Reason for Bitcoin Reversal, Sees BTC Approaching Next Resistance Levels – Here Are His Targets

    May 14, 2026

    Bitcoin, Ethereum and XRP Price Analysis: What’s Coming Next?

    May 13, 2026

    Wells Fargo Boosts Ethereum ETF Holdings in Q1

    May 13, 2026

    Why Market Experts Are Still Predicting A Rise Above $10,000

    May 13, 2026

    Bitmine ETH Holdings Cross 5.2 Million—CEO Announces New Phase For Crypto Markets

    May 12, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026

    Bitcoin Just Entered A Deceptive Territory, Here’s What You Should Know

    May 14, 2026

    XRP Ledger Hits Record High In 10K+ Wallets: Santiment

    May 13, 2026

    Mysterious Bitcoin Whale Transfers $40B After Years Of Silence

    May 13, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    UBOX Taps ClawWorks to Accelerate Independent AI Agent Economics

    May 14, 2026

    UXLINK And Origins Network Partner To Power Scalable AI-Driven Web3 Applications Using Decentralized Computing

    May 13, 2026

    Ripple Shares DPRK Threat Data on Fraud Domains, Wallets, Campaigns

    May 5, 2026

    Digital Asset Security Moves Beyond Keys as Bitgo Adds 5-Layer Checks

    May 1, 2026

    Defillama Confirms April 2026 as Crypto’s Most-Hacked Month With 30 Incidents

    May 1, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026
  • Web 3
    1. Gaming
    2. View All

    NUMINE Joins Outer Ring MMO for the Expansion of Web3 Gaming Experiences

    May 13, 2026

    GMatrixs And MiniverseCore Join Forces To Unlock Web3 Gaming Experience With Cross-Chain DApp, DeFi Applications

    May 11, 2026

    The Identity Crisis of 2026: NFTs, AI Agents and Trust on the Agentic Web

    May 11, 2026

    DTCC’s May 2026 Tokenization Announcement Explained: What It Means for U.S. Securities and Real-World Assets

    May 11, 2026

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Michael Saylor Says the Transparency Act in the US Congress Will Positively Impact Bitcoin! Here Are the Details

    May 14, 2026

    Consensys Urges SEC to Exempt Self-Custody Wallets, Citing Regulatory Gap for 99% of Tokens

    May 14, 2026

    Tether launches decentralized local AI using Isaac Asimov’s Psychohistory straight out of Foundation

    May 11, 2026

    Has Donald Trump been a net positive for Bitcoin or created an unbreakable partisan divide?

    May 10, 2026

    BlackRock looks to sidestep Clarity yield issues, filing for two new tokenized money market funds

    May 10, 2026

    Cardano’s Charles Hoskinson says the future of crypto wallets will be inside iPhones and Androids

    May 8, 2026

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026
  • Analysis

    Trump’s CEO-filled China visit can decide whether Bitcoin’s $80,000 risk rally survives this week

    May 14, 2026

    Wall Street is buying XRP while Binance traders keep betting against it

    May 13, 2026

    Is a Drop Below $1 Coming Next?

    May 13, 2026

    UB Price Breakout Enters Discovery Phase

    May 13, 2026

    Billions Network Rally Accelerates After Binance Futures Launch

    May 13, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Coinbase went down for over 5 hours after missing earnings. Bulls still see a path to $300 billion by 2030

    May 8, 2026

    Coinbase cuts 14% of staff as Armstrong ties cost reset to AI and market volatility

    May 6, 2026

    Bitcoin is still in charge

    May 3, 2026

    CLARITY Act stablecoin fight shifts from yield to who captures digital-dollar economics

    April 29, 2026

    U.S. CFTC in talks with every major pro sports league on policing prediction markets

    May 14, 2026

    Monad Backs Stablecoin Startup Rain for Global Visa Payments

    May 14, 2026

    Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

    May 14, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
Security and Privacy

DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown

September 28, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Successors to the QakBot malware have emerged despite the disruption to QakBot infrastructure by an international law enforcement operation led by the FBI in August 2023.

Cofense, a phishing detection solution provider, has observed new phishing campaigns that use the same infection tactics QakBot was known to deploy. However, these recent campaigns deliver two new malware families, DarkGate and PikaBot.

One phishing campaign began spreading DarkGate malware in September and has grown to become one of the most advanced phishing campaigns active in the threat landscape, according to a report by Cofense. The campaign has evolved to use evasive tactics and anti-analysis techniques to continue distributing DarkGate and, more recently, PikaBot.

Typical QakBot tactics observed in the DarkGate and PikaBot campaigns included:

  • Hijacked email threads as the initial infection
  • URLs with unique patterns that limit user access
  • An infection chain nearly identical to QakBot delivery

Cofense researchers believe that some previous QakBot users have shifted to using DarkGate and/or PikaBot.

Some of these campaigns are “undoubtedly high-level threat[s] due to the tactics, techniques, and procedures (TTPs) that enable the phishing emails to reach intended targets as well as the advanced capabilities of the malware being delivered,” added the report.

Most of the post-QakBot takedown campaigns involve different infection chains.

“Almost as if the threat actors were testing different malware delivery options,” Cofense said.

However, the most used infection chain shows many similarities with some QakBot campaigns conducted in May 2023.

“The campaign begins with a hijacked email thread to bait users into interacting with a URL that has added layers that limit access to the malicious payload only to users that meet specific requirements set by the threat actors (location and internet browser),” outlined Cofense researchers.

See also  ASTER Price Jumps Double Digits as Rocket Launch Incentives Ignite Whale Activity

“This URL downloads a ZIP archive that contains a JS file that is a JS Dropper, which is a JavaScript application used to reach out to another URL to download and run malware. At this stage, a user has been successfully infected with either the DarkGate or PikaBot malware.”

Some of these newly observed campaigns disseminated a high volume of emails to a wide range of industries, putting targets at risk of more sophisticated threats like reconnaissance malware and ransomware.

Read more: FBI-Led Operation Duck Hunt Shuts Down QakBot Malware

What are the DarkGate and PikaBot Malware Families?

DarkGate and PikaBot are both considered advanced malware with loader capabilities and anti-analysis behavior.

DarkGate is a versatile malware toolset, typically spread through spam email attachments or malicious links, that has been active since 2017. It is equipped with various capabilities, including data stealing, cryptocurrency mining and remote control of infected systems.

Once installed, DarkGate can steal a variety of sensitive information, including passwords, credit card numbers and personal documents. It can also mine for cryptocurrency, which can use the victim’s computer resources to generate money for the attackers.

In addition, DarkGate can allow attackers to remotely control the infected system, which could be used to install other malware, steal data or launch attacks against other systems.

PikaBot is a new malware family first observed in 2023. It is classified as a loader due to its ability to deliver additional malware payloads. It contains several evasive techniques to avoid sandboxes, virtual machines and other debugging techniques.

PikaBot is typically spread through phishing attacks or by exploiting vulnerabilities in software. Once installed, PikaBot can be controlled by attackers remotely.

See also  Bitcoin LTH Supply Activity Continues To Rise — Further Downside For Price?

It has been observed to exclude infecting machines in Commonwealth of Independent States (CIS) countries – all members of the former Soviet Union.

How Was QakBot’s Infrastructure Taken Down?

In August, the FBI led Operation Duck Hunt, a multinational law enforcement operation that allegedly dismantled QakBot.

To do this, the FBI gained access to QakBot’s admin computers, which helped law enforcement map out the server infrastructure used in the botnet’s operation. It then seized 52 servers, which it said would “permanently dismantle” the botnet, and redirected QakBot’s traffic to servers controlled by the Bureau, pointing victims to download an uninstaller.

In an additional announcement, the US Department of Justice (DoJ) said the FBI had identified over 700,000 infected computers worldwide, including more than 200,000 in the US.

The DoJ also announced it seized over $8.6m in cryptocurrency from the QakBot cybercriminal organization. This money will be returned to the victims.

While the cybersecurity community has generally praised Operation Duck Hunt, voices doubted the real impact of the takedown.

The possibility that threat actors would be moving to use other malware families to deploy the same type of malicious campaigns was one of the criticisms about the efficacy of such an operation.

Read more: FBI’s QakBot Takedown Raises Questions: ‘Dismantled’ or Just a Temporary Setback?

Activity DarkGate PikaBot QakBot surge Takedown Wake
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin Price Holds Near $82,000 As ETF Inflows Surge And CLARITY Act Battle Intensifies

May 12, 2026

BNB Chain’s China-related tokenized stocks surge to $9.3M in value

May 12, 2026

SUI Breakout Gains Momentum—Can the Price Surge Another 20% in May?

May 10, 2026

Ethereum Large-Holder Activity Drives Short-Term Consolidation, Instability — Details

May 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

UQUID Joins Forces with Veritas Protocol to Drive Web3 eCommerce DApps With AI Security

November 7, 2025

NEXUS and CertiK Join Forces to Strengthen CROSS Web3 Gaming Security

December 25, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

U.S. CFTC in talks with every major pro sports league on policing prediction markets

May 14, 2026

Monad Backs Stablecoin Startup Rain for Global Visa Payments

May 14, 2026

Senate Confirms Bitcoin Friendly Kevin Warsh As Fed Chair Ahead Of Clarity Act Vote

May 14, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.