Qadars

First seen
2013-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-19 03:21:11
Profile updated
2026-07-07 13:47:09

Targeted industries: financial-services

Targeted regions: country_code:ca country_code:fr country_code:nl country_code:za

Context

Qadars is a banking trojan primarily targeting financial institutions. It is known to steal user credentials and manipulate web sessions to perform fraudulent transactions.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Qadars_Auto (yara-rule)

Reports & references

  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Qadars (report)
  • ESET — Qadars A Banking Trojan With The Netherlands In Its Sights (report)
  • johannesbader.ch — The Dga Of Qadars (report)
  • info.phishlabs.com — Dissecting The Qadars Banking Trojan (report)
  • securityintelligence.com — Meanwhile Britain Qadars V3 Hardens Evasion Targets 18 Uk Banks (report)
  • securityintelligence.com — An Analysis Of The Qadars Trojan (report)

External references