logo

Qakbot Malware Continues to Morph

ID: 4819ff6d-1611-582f-b766-b14bcbc53fd1

STIX ID: report--4819ff6d-1611-582f-b766-b14bcbc53fd1

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

**Qakbot campaigns using OneNote/CHM delivery:** This report documents active Qakbot spam campaigns where OneNote attachments embed ISO/CHM content that triggers a base64 PowerShell payload to download and execute a Qakbot DLL (run via rundll32), enabling credential theft and follow-on payloads such as Cobalt Strike; the report provides attack-chain analysis, MITRE technique mappings, IOCs (hashes for .eml, .one, .chm files), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.