logo

New Qbot malware variant uses fake Adobe installer popup for evasion

ID: 88443e21-a4b8-5170-b240-b435b3c83d51

STIX ID: report--88443e21-a4b8-5170-b240-b435b3c83d51

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-02-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed renewed Qakbot (QBot) activity with up to 10 new builds since mid-December that employ MSI/CAB droppers and a bogus Adobe installer prompt to deploy a DLL; the variants use stronger obfuscation (AES-256 over XOR), perform AV and virtualization checks to evade analysis, and continue to act as loaders for ransomware and other malicious payloads—warranting close monitoring and updated detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.