QBot: The Rise, Evolution, and Resilience of a Cyberthreat
ID: e8d83b7a-8ce6-5e26-8021-87bca3c551b6
STIX ID: report--e8d83b7a-8ce6-5e26-8021-87bca3c551b6
Feed Name: Halcyon Blog
QBot (QakBot/Pinkslipbot) has evolved from a banking trojan into a versatile, modular malware platform that facilitates data theft, network propagation, remote code execution, and delivery of secondary payloads such as ransomware. Recent activity links QBot to the Black Basta ransomware group, with campaigns initiated via phishing and malicious URLs and accelerated by techniques including DLL hijacking targeting Windows 10 WordPad; the report highlights QBot's tiered C2 infrastructure, fast exfiltration timeline, and the need for rapid, multi-layered defensive responses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
