Threat Advisory: Qakbot Activity Is Rising
ID: 9bb7f2c1-aeb6-5c07-80f0-067828d313fc
STIX ID: report--9bb7f2c1-aeb6-5c07-80f0-067828d313fc
Feed Name: Huntress Blog
QakBot is an actively maintained, modular malware family that has surged recently (a reported 400% increase and several hundred incidents) and has evolved from a banking infostealer into botnets and a ransomware delivery agent. The report details primary infection through emailed HTML/ZIP attachments that lead users to execute LNKs which mount ISOs, followed by DLL execution via regsvr32/rundll32 and DLL sideloading, describes persistence and lateral movement techniques (including SMB propagation), notes evasion of AV via process injection and staged behavior, and provides mitigations (email filtering, disabling ISO mounting, disabling admin shares, rapid isolation, patching, and EDR).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
