Qakbot Strikes Back: Understanding the Threat
ID: 52afe69c-147c-5ce7-abf1-57b0b4924816
STIX ID: report--52afe69c-147c-5ce7-abf1-57b0b4924816
Feed Name: Binary Defense Blog
Threat Score
QakBot (QBot) has resurfaced after a 2023 takedown; recent samples are distributed via phishing (including IRS-themed lures), masquerade as Adobe installer UI, create restore-point-based persistence via srtasks.exe, drop a KROST.dll payload in AppData\Roaming, and execute via hidden rundll32—Binary Defense and Microsoft published behavior-based detections and Sentinel queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
