Qakbot Upgrades to Stealthier Persistence Method
ID: aac96d8d-c0d3-5590-91c4-935b5b2e40e3
STIX ID: report--aac96d8d-c0d3-5590-91c4-935b5b2e40e3
Feed Name: Binary Defense Blog
Qakbot (a versatile banking trojan) has been updated to combine its loader and bot into a single DLL, employ stealthy delivery via Excel 4 macros distributed by spam campaigns, and shift runtime configuration/logging into encrypted registry entries; post-compromise activity includes deploying Cobalt Strike and ransomware families (ProLock, Egregor). The report describes infection flow, evasive persistence (scheduled tasks, dynamic Run key installation on shutdown/resume), low initial AV detection rates, and provides IoCs and a scheduled task example.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
