Exploring the QBOT Attack Pattern
ID: faa774af-b948-5571-a577-7e7de58a6025
STIX ID: report--faa774af-b948-5571-a577-7e7de58a6025
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs analyzed a QBOT (QAKBOT) sample, describing its execution chain (initial regsvr32-based DLL load and explorer injection), defense-evasion (watchdog process checks, Defender exclusions), persistence (user registry Run keys), privilege escalation (schtasks to SYSTEM), network infrastructure (138 IPs and 338 related samples), configuration extraction tooling, YARA detections, and downloadable ECS/STIX artifacts for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
