Qadars
- First seen
- 2013-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-19 03:21:11
- Profile updated
- 2026-07-07 13:47:09
Targeted industries: financial-services
Targeted regions: country_code:ca country_code:fr country_code:nl country_code:za
Context
Qadars is a banking trojan primarily targeting financial institutions. It is known to steal user credentials and manipulate web sessions to perform fraudulent transactions.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Qadars_Auto (yara-rule)
Reports & references
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Qadars (report)
- ESET — Qadars A Banking Trojan With The Netherlands In Its Sights (report)
- johannesbader.ch — The Dga Of Qadars (report)
- info.phishlabs.com — Dissecting The Qadars Banking Trojan (report)
- securityintelligence.com — Meanwhile Britain Qadars V3 Hardens Evasion Targets 18 Uk Banks (report)
- securityintelligence.com — An Analysis Of The Qadars Trojan (report)