Are DarkGate and PikaBot the new QakBot?
ID: 4c357814-7b69-5fb8-948f-e8b62488d6d3
STIX ID: report--4c357814-7b69-5fb8-948f-e8b62488d6d3
Feed Name: Cofense Blog
Cofense Intelligence reports an active, evolving phishing campaign (beginning September) that disseminates DarkGate and PikaBot via hijacked email threads and sophisticated delivery chains (JS droppers, Excel‑DNA, VBS, LNK). The campaign uses evasive URLs that limit access by location/browser, employs anti-analysis and sandbox-evasion techniques, and functions as a loader capable of delivering additional payloads — increasing risk of reconnaissance tools, cryptocurrency miners, and ransomware; the activity shows strong TTP overlap with QakBot-affiliated campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
