logo

Qakbot Resurfaces with new Playbook

ID: a4da027d-16ee-5307-9f34-38084c655d68

STIX ID: report--a4da027d-16ee-5307-9f34-38084c655d68

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report describes an active Qakbot phishing campaign where a password‑protected ZIP delivers an ISO that presents a fake PDF shortcut (.lnk); executing it runs a bundled calc.exe which DLL‑sideloads a malicious WindowsCodecs.dll to invoke 7533.dll via regsvr32, enabling process injection and credential theft. The analysis includes the full infection chain, MITRE ATT&CK technique mappings (phishing, user execution, DLL side‑loading, process injection), file hashes for IOCs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.