Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

April 24, 2026

REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

April 24, 2026

Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

April 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    US Military Tests Bitcoin Node for Cybersecurity Research

    April 24, 2026

    Crypto Veterans Flip Bullish on Bitcoin As BTC Trades at $78,000 – Here Are Their Price Targets

    April 24, 2026

    The market repriced DeFi in just 48 hours

    April 24, 2026

    Ethereum Near Key Zone After 36% Gain

    April 24, 2026

    Bitmine Stakes 61,232 ETH Worth $142M

    April 22, 2026

    Ethereum Targets Lower Range As Resistance Zone Comes Into Play

    April 22, 2026

    Ethereum Price Rises, But On-Chain Data Signals Weak Demand —What’s Next for ETH?

    April 21, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    What’s Happening Between ETH And The Financial Systems?

    April 24, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    Crypto Billionaire Justin Sun Files Lawsuit Against Trump-Linked World Liberty Financial Over ‘Wrongfully’ Frozen Tokens

    April 23, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Pyth Network to determine outcomes in Kalshi’s commodities expansion

    April 24, 2026

    The question isn’t whether privacy. It’s what sort of privacy

    April 24, 2026

    Ripple Joins BIS Taskforce For Cross Border Payments Expansion

    April 24, 2026

    ZetaChain Onboards Kimi and Alibaba Qwen as AI Models Go Cross-Chain

    April 23, 2026

    How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

    April 22, 2026

    North Korean Blamed for $290m KelpDAO Crypto Heist

    April 21, 2026

    Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

    April 21, 2026

    Ripple’s Schwartz Flags DeFi Bridge Trade-Offs After KelpDAO Incident

    April 21, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026
  • Web 3
    1. Gaming
    2. View All

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Zach Lowe: Celtics’ offense struggles since Tatum’s return, Luka Doncic’s historic scoring season, and LeBron’s pivotal role in Lakers’ surprise playoff success

    April 24, 2026

    GameFi is effectively dead as 93% of projects collapse

    April 24, 2026

    More than 90% of Web3 games failed after $15 billion boom as gamers never showed up: Caladan

    April 23, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026

    Tron’s Justin Sun sues Trump-linked World Liberty Financial over frozen assets

    April 24, 2026

    New York sues Coinbase, Gemini over prediction market offerings

    April 24, 2026

    Explosive Class Action Alleges False Advertising and Market Manipulation in Crypto AI Project

    April 23, 2026

    Cardano development teams wants almost $50 million for Bitcoin DeFi and Vision 2030

    April 24, 2026

    Oil tanker attacked after falling for crypto scam granting fake Strait of Hormuz safe passage

    April 21, 2026

    Six years after “DeFi Summer” is the sun already setting on the decentralized finance revolution?

    April 20, 2026

    Bitcoin network activity just hit an 8-year low — has Wall Street replaced retail in the market?

    April 19, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026
  • Analysis

    SPK Price Explodes After Breakout, But Overbought Signals Flash Warning

    April 23, 2026

    US Bankers association push for 60 day pause to stop stablecoin rules going live

    April 23, 2026

    STABLE Price Jumps 15% After CEO Spotlight, But Is This Rally Sustainable?

    April 23, 2026

    ZEC Price Prediction: Zcash Retests Key Level

    April 23, 2026

    Monero Price Analysis: XMR Presses $400 Resistance

    April 23, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Over 80% of Bitcoin ETF assets hit Coinbase custody choke point with $74B at risk

    April 13, 2026

    FTX begins $2.2B payout. Can Bitcoin absorb another liquidity test?

    March 31, 2026

    BlinkEx investment platform infrastructure – matching, risk controls, reliability

    March 21, 2026

    Over $2B in “lost” Bitcoin to hit markets this month creating sell pressure within fragile $67k–$74k range

    March 20, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown
Security and Privacy

DarkGate and PikaBot Activity Surge in the Wake of QakBot Takedown

September 28, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Successors to the QakBot malware have emerged despite the disruption to QakBot infrastructure by an international law enforcement operation led by the FBI in August 2023.

Cofense, a phishing detection solution provider, has observed new phishing campaigns that use the same infection tactics QakBot was known to deploy. However, these recent campaigns deliver two new malware families, DarkGate and PikaBot.

One phishing campaign began spreading DarkGate malware in September and has grown to become one of the most advanced phishing campaigns active in the threat landscape, according to a report by Cofense. The campaign has evolved to use evasive tactics and anti-analysis techniques to continue distributing DarkGate and, more recently, PikaBot.

Typical QakBot tactics observed in the DarkGate and PikaBot campaigns included:

  • Hijacked email threads as the initial infection
  • URLs with unique patterns that limit user access
  • An infection chain nearly identical to QakBot delivery

Cofense researchers believe that some previous QakBot users have shifted to using DarkGate and/or PikaBot.

Some of these campaigns are “undoubtedly high-level threat[s] due to the tactics, techniques, and procedures (TTPs) that enable the phishing emails to reach intended targets as well as the advanced capabilities of the malware being delivered,” added the report.

Most of the post-QakBot takedown campaigns involve different infection chains.

“Almost as if the threat actors were testing different malware delivery options,” Cofense said.

However, the most used infection chain shows many similarities with some QakBot campaigns conducted in May 2023.

“The campaign begins with a hijacked email thread to bait users into interacting with a URL that has added layers that limit access to the malicious payload only to users that meet specific requirements set by the threat actors (location and internet browser),” outlined Cofense researchers.

See also  Romance Baiting Losses Surge 40% Annually

“This URL downloads a ZIP archive that contains a JS file that is a JS Dropper, which is a JavaScript application used to reach out to another URL to download and run malware. At this stage, a user has been successfully infected with either the DarkGate or PikaBot malware.”

Some of these newly observed campaigns disseminated a high volume of emails to a wide range of industries, putting targets at risk of more sophisticated threats like reconnaissance malware and ransomware.

Read more: FBI-Led Operation Duck Hunt Shuts Down QakBot Malware

What are the DarkGate and PikaBot Malware Families?

DarkGate and PikaBot are both considered advanced malware with loader capabilities and anti-analysis behavior.

DarkGate is a versatile malware toolset, typically spread through spam email attachments or malicious links, that has been active since 2017. It is equipped with various capabilities, including data stealing, cryptocurrency mining and remote control of infected systems.

Once installed, DarkGate can steal a variety of sensitive information, including passwords, credit card numbers and personal documents. It can also mine for cryptocurrency, which can use the victim’s computer resources to generate money for the attackers.

In addition, DarkGate can allow attackers to remotely control the infected system, which could be used to install other malware, steal data or launch attacks against other systems.

PikaBot is a new malware family first observed in 2023. It is classified as a loader due to its ability to deliver additional malware payloads. It contains several evasive techniques to avoid sandboxes, virtual machines and other debugging techniques.

PikaBot is typically spread through phishing attacks or by exploiting vulnerabilities in software. Once installed, PikaBot can be controlled by attackers remotely.

See also  Belarus unveils register for cryptocurrency wallets used in criminal activity

It has been observed to exclude infecting machines in Commonwealth of Independent States (CIS) countries – all members of the former Soviet Union.

How Was QakBot’s Infrastructure Taken Down?

In August, the FBI led Operation Duck Hunt, a multinational law enforcement operation that allegedly dismantled QakBot.

To do this, the FBI gained access to QakBot’s admin computers, which helped law enforcement map out the server infrastructure used in the botnet’s operation. It then seized 52 servers, which it said would “permanently dismantle” the botnet, and redirected QakBot’s traffic to servers controlled by the Bureau, pointing victims to download an uninstaller.

In an additional announcement, the US Department of Justice (DoJ) said the FBI had identified over 700,000 infected computers worldwide, including more than 200,000 in the US.

The DoJ also announced it seized over $8.6m in cryptocurrency from the QakBot cybercriminal organization. This money will be returned to the victims.

While the cybersecurity community has generally praised Operation Duck Hunt, voices doubted the real impact of the takedown.

The possibility that threat actors would be moving to use other malware families to deploy the same type of malicious campaigns was one of the criticisms about the efficacy of such an operation.

Read more: FBI’s QakBot Takedown Raises Questions: ‘Dismantled’ or Just a Temporary Setback?

Activity DarkGate PikaBot QakBot surge Takedown Wake
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Monthly Active Addresses Explode – Analyzing the Surge in Layer-1 and Layer-2 Network Utility

April 23, 2026

How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

April 22, 2026

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026

Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

April 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

US frees up billions for banks while quietly admitting SVB’s core failure never went away

April 4, 2026

All social program benefits can be distributed onchain: Compliance exec

February 17, 2026

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

April 24, 2026

REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

April 24, 2026

Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

April 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.