logo

Qakbot’s Evolution Continues with New Strategies

ID: aab42ec2-1232-5e30-b9cb-2e29c58b5705

STIX ID: report--aab42ec2-1232-5e30-b9cb-2e29c58b5705

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-17

Date Updated: 2026-07-17

...
...

This report describes an active Qakbot spam campaign that delivers malware through malicious Microsoft OneNote attachments: opening the OneNote drops and executes an attachment.hta via mshta.exe, which stores obfuscated data in the registry, uses curl to download a .dat (persisted as a .png Qakbot DLL) to %ProgramData% and launches it with rundll32.exe, followed by process injection for data theft. The analysis includes the full infection chain, observed behaviors, recommended mitigations, MITRE ATT&CK mappings, and specific IOCs (SHA256 hashes and a download URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.