HomeSample Page

Sample Page Title


Oct 05, 2023NewsroomRansomware / Malware

QakBot

Regardless of the disruption to its infrastructure, the risk actors behind the QakBot malware have been linked to an ongoing phishing marketing campaign since early August 2023 that led to the supply of Ransom Knight (aka Cyclops) ransomware and Remcos RAT.

This means that “the regulation enforcement operation could not have impacted Qakbot operators’ spam supply infrastructure however moderately solely their command-and-control (C2) servers,” Cisco Talos researcher Guilherme Venere mentioned in a brand new report revealed right now.

The exercise has been attributed with reasonable confidence by the cybersecurity agency to QakBot associates. There isn’t a proof thus far that the risk actors have resumed distributing the malware loader itself post-infrastructure takedown.

Cybersecurity

QakBot, additionally known as QBot and Pinkslipbot, originated as a Home windows-based banking trojan in 2007 and subsequently developed capabilities to ship further payloads, together with ransomware. In late August 2023, the infamous malware operation was dealt a blow as a part of an operation named Duck Hunt.

Ransom Knight and Remcos RAT

The newest exercise, which commenced simply earlier than the takedown, begins with a malicious LNK file probably distributed through phishing emails that, when launched, detonates the an infection and finally deploys the Ransom Knight ransomware, a current rebrand of the Cyclops ransomware-as-a-service (RaaS) scheme.

The ZIP archives containing the LNK information have additionally been noticed incorporating Excel add-in (.XLL) information to propagate the Remcos RAT, which facilitates persistent backdoor entry to the endpoints.

Cybersecurity

Among the file names getting used within the marketing campaign are written in Italian, which suggests the attackers are concentrating on customers in that area.

“Although we have now not seen the risk actors distributing Qakbot post-infrastructure takedown, we assess the malware will probably proceed to pose a major risk shifting ahead,” Venere mentioned.

“Given the operators stay energetic, they could select to rebuild Qakbot infrastructure to completely resume their pre-takedown exercise.”

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles