MALLARD SPIDER is CrowdStrike's designation for the financially motivated cybercriminal operators behind the QakBot (also known as Qbot or Pinkslipbot) malware, which first emerged in late 2007. Originally developed as a banking trojan, the group has continuously evolved its operations and the QakBot malware into a versatile, modular botnet and malware loader. Their primary motivation is financial gain, achieved through stealing sensitive financial data, facilitating fraudulent activities, and acting as an initial access broker for various ransomware groups. MALLARD SPIDER is assessed with high confidence to be of Russian origin and is notably resilient, demonstrating prolonged activity over 15 years despite significant law enforcement disruptions. This group is distinguished by its constant adaptation and its 'Swiss Army knife' approach to cybercrime, offering a broad range of malicious capabilities and serving as a critical component in the cybercrime ecosystem.