New Qbot malware variant uses fake Adobe installer popup for evasion
ID: 88443e21-a4b8-5170-b240-b435b3c83d51
STIX ID: report--88443e21-a4b8-5170-b240-b435b3c83d51
Feed Name: Bleeping Computer
Threat Score
Researchers observed renewed Qakbot (QBot) activity with up to 10 new builds since mid-December that employ MSI/CAB droppers and a bogus Adobe installer prompt to deploy a DLL; the variants use stronger obfuscation (AES-256 over XOR), perform AV and virtualization checks to evade analysis, and continue to act as loaders for ransomware and other malicious payloads—warranting close monitoring and updated detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
