Netskope Threat Labs

Qhost

ATP Sandbox Adv. HeuristicsAV

Qhost is a trojan and dropper that modifies DNS settings and the local hosts file to redirect victims to malicious websites. By controlling name resolution, it can steer banking sessions and software updates to criminal controlled servers without touching the browser itself. The family is among the oldest DNS hijackers, and its technique remains relevant wherever endpoint name resolution goes unmonitored.

First seen
January 2022
Last seen
September 2026
QHost
Alert Name
ByteCode-MSIL.Trojan.QHost
Dropped:Trojan.QHost.MDC
Gen:Trojan.Qhost.1
Image.Trojan.QHost
MacOS.Trojan.QHost
Script-BAT.Trojan.QHost
Script-JS.Trojan.QHost
Script-WScript.Trojan.QHost
Trojan.BAT.Qhost.BG
Trojan.Clicker.Qhost.A