Qakbot Delivered Through CVE-2022-30190 (Follina)
ID: 3935935b-ae42-52c4-a5a3-17932a4ba3f5
STIX ID: report--3935935b-ae42-52c4-a5a3-17932a4ba3f5
Feed Name: FortiGuard Threat Signals
FortiGuard Labs reports active in-the-wild exploitation of the unpatched Windows MSDT vulnerability CVE-2022-30190 (Follina) used to deliver Qakbot (Qbot/Pinkslipbot). The advisory describes the attack chain—malicious HTML attachments that drop ZIP/IMG files containing a Qakbot DLL or a Word file that abuses MSDT to fetch and execute Qakbot—notes associated AV/IPS signatures and mitigations (FortiEDR, CDR, WebFiltering), and highlights the risk of ransomware deployment following Qakbot infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
