logo

Threat Advisory: Qakbot Activity Is Rising

ID: 9bb7f2c1-aeb6-5c07-80f0-067828d313fc

STIX ID: report--9bb7f2c1-aeb6-5c07-80f0-067828d313fc

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-02-24

Date Updated: 2026-04-28

...
...

QakBot is an actively maintained, modular malware family that has surged recently (a reported 400% increase and several hundred incidents) and has evolved from a banking infostealer into botnets and a ransomware delivery agent. The report details primary infection through emailed HTML/ZIP attachments that lead users to execute LNKs which mount ISOs, followed by DLL execution via regsvr32/rundll32 and DLL sideloading, describes persistence and lateral movement techniques (including SMB propagation), notes evasion of AV via process injection and staged behavior, and provides mitigations (email filtering, disabling ISO mounting, disabling admin shares, rapid isolation, patching, and EDR).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.