Description
Qhost is a trojan and dropper that modifies DNS settings and the local hosts file to redirect victims to malicious websites. By controlling name resolution, it can steer banking sessions and software updates to criminal controlled servers without touching the browser itself. The family is among the oldest DNS hijackers, and its technique remains relevant wherever endpoint name resolution goes unmonitored.
Stats
- First seen
- January 2022
- Last seen
- September 2026
Also known as
QHost
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.QHost |
| Dropped:Trojan.QHost.MDC |
| Gen:Trojan.Qhost.1 |
| Image.Trojan.QHost |
| MacOS.Trojan.QHost |
| Script-BAT.Trojan.QHost |
| Script-JS.Trojan.QHost |
| Script-WScript.Trojan.QHost |
| Trojan.BAT.Qhost.BG |
| Trojan.Clicker.Qhost.A |