Qakbot Resurfaces with new Playbook
ID: a4da027d-16ee-5307-9f34-38084c655d68
STIX ID: report--a4da027d-16ee-5307-9f34-38084c655d68
Feed Name: Cyble Blog
This report describes an active Qakbot phishing campaign where a password‑protected ZIP delivers an ISO that presents a fake PDF shortcut (.lnk); executing it runs a bundled calc.exe which DLL‑sideloads a malicious WindowsCodecs.dll to invoke 7533.dll via regsvr32, enabling process injection and credential theft. The analysis includes the full infection chain, MITRE ATT&CK technique mappings (phishing, user execution, DLL side‑loading, process injection), file hashes for IOCs, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
