Qakbot Malware Continues to Morph
ID: 4819ff6d-1611-582f-b766-b14bcbc53fd1
STIX ID: report--4819ff6d-1611-582f-b766-b14bcbc53fd1
Feed Name: Cyble Blog
Threat Score
**Qakbot campaigns using OneNote/CHM delivery:** This report documents active Qakbot spam campaigns where OneNote attachments embed ISO/CHM content that triggers a base64 PowerShell payload to download and execute a Qakbot DLL (run via rundll32), enabling credential theft and follow-on payloads such as Cobalt Strike; the report provides attack-chain analysis, MITRE technique mappings, IOCs (hashes for .eml, .one, .chm files), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
