Qakbot's backbot: FBI-led takedown keeps crims at bay for just 3 months
ID: f077981d-f5b3-535f-971d-cfc186fff6a5
STIX ID: report--f077981d-f5b3-535f-971d-cfc186fff6a5
Feed Name: The Register (Security)
Threat Score
Multiple security vendors report a resurgence of the Qakbot botnet delivered via phishing PDFs that trick recipients into downloading an updated Qakbot payload (version 0x500). The new samples are 64-bit, use AES for network encryption, and contact C2 paths (/teorema505); activity is currently low-volume but confirmed by Microsoft, Zscaler, and Proofpoint, and occurs months after Operation Duck Hunt disrupted the botnet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
