logo

Exploring the QBOT Attack Pattern

ID: faa774af-b948-5571-a577-7e7de58a6025

STIX ID: report--faa774af-b948-5571-a577-7e7de58a6025

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2022-08-22

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzed a QBOT (QAKBOT) sample, describing its execution chain (initial regsvr32-based DLL load and explorer injection), defense-evasion (watchdog process checks, Defender exclusions), persistence (user registry Run keys), privilege escalation (schtasks to SYSTEM), network infrastructure (138 IPs and 338 related samples), configuration extraction tooling, YARA detections, and downloadable ECS/STIX artifacts for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.