Detecting QakBot: WSF attachments, OneNote files, and generic attack surface reduction · Blog · Sublime Security
ID: 18705be7-239f-50c7-bd0b-0ec9467800ec
STIX ID: report--18705be7-239f-50c7-bd0b-0ec9467800ec
Feed Name: Sublime Security Blog
Threat Score
This report outlines QakBot’s long-term evolution and recent activity, describing new distribution techniques observed in 2022–2023 (notably .wsf-based phishing with ZIP attachments and OneNote-based delivery), payload execution behaviors (DLL dropped to C:\ProgramData and executed via rundll32.exe), and includes MQL detection rules and attack surface reduction recommendations to detect and hunt associated campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
