#qbot

:mastodon: deciodecio@infosec.exchange
2025-01-21

"In addition to the new backConnect malware developed by Qbot operators, research has emerged tying zloader[4] activity to that of the BlackBasta ransomware operation. It is highly likely this new side loading backConnect malware has been or is going to be utilized to further ransomware attacks."
⬇️
"Qbot is Back.Connect"
👇
medium.com/walmartglobaltech/q

#CyberVeille #qbot #malware #BlackBasta

2024-07-24

Proofpoint's Daniel Blackford is set to take the stage at Black Hat USA for a talk on law enforcement takedowns.

#OperationEndgame is just one botnet disruption that has made recent headlines. #Emotet, #Qbot, #Lockbit, and #Smokeloader are a few others.

Law enforcement cooperates on takedowns -- but are they effective? Be sure to catch Daniel's talk to examine the data!

Avoid the Hack! :donor:avoidthehack@infosec.exchange
2024-02-16

New #Qbot #malware variant uses fake Adobe installer popup for evasion

The misleading popup this campaign spawns “Adobe Setup” installs itself regardless of what you click.

As always be careful what you click and download.

#cybersecurity #security #infosec

bleepingcomputer.com/news/secu

2024-01-10

Do #takedowns help stop #cybercriminal activity? 🤔

They do, to a certain extent, according to @recordedfuture's 2023 Adversary Infrastructure Report.

📰 Read story here: infosecurity-magazine.com/news

#QakBot #QBot #Emotet #CobaltStrike #RAT #botnet #infostealer

2023-12-18
2023-10-06

Qakbot Gang Still Active Despite #FBI Takedown 🦆🔫❌

A #Qakbot affiliate is still deploying Ransom Knight #ransomware and the Remcos #backdoor via phishing emails, according to @TalosSecurity. #Qbot

infosecurity-magazine.com/news

2023-08-30

"Duck Hunt" international police operation disrupts:
—700,000 computers infected with Qakbot dropper
—ransomware wielders relying on #Qbot
—52 servers used by criminals (seized)
—$9 million worth of cryptocurrency (seized)
databreachtoday.com/operation-
@daveperera

#FBI 主導の #ダックハント 作戦でクアクボットを撃墜」: The Register

「フランス、ドイツ、オランダ、英国、ルーマニア、ラトビアからの支援により、法執行機関は過去3日間で、 #QBot ネットワークを維持するために使用されていた米国内外の52のサーバーを押収した。」

theregister.com/2023/08/29/duc

#prattohome #TheResister

2023-08-29

And down goes Quakbot!

One of the most prolific #malware loaders over the last 15 years has been dismantled by the FBI.

How did they do it? By implementing a reverse uno card of sorts---making infected computers to download an uninstaller file.

A novel approach to getting rid of malware and 700K computers say thank you. fbi.gov/news/stories/fbi-partn #cybersecurity #security #qbot

chris actuallackattack
2023-08-29

pew pew pew!! Bye bye,
Uninstaller packages were it's only weakness lol
techcrunch.com/2023/08/29/fbi-

2023-08-29

U.S. Hacks QakBot, Quietly Removes Botnet Infections - The U.S. government today announced a coordinated crackdown against QakBot, a comp... krebsonsecurity.com/2023/08/u- #federalbureauofinvestigation #u.s.departmentofjustice #latestwarnings #thecomingstorm #martinestrada #ransomware #donalway #qakbot #qbot #doj #fbi

「マルウェア ローダーの詳細: 今年これまでの攻撃の 80% を引き起こしたビッグ 3 」: The Register

#QBot#SocGholish#Raspberry Robin の 3 つのマルウェア ローダーが、今年これまでに観察されたコンピュータやネットワークに対する攻撃の 80% の原因となっています。 」

theregister.com/2023/08/28/top

#prattohome #TheResister

Just Another Blue TeamerLeeArchinal@ioc.exchange
2023-08-26

Good day everyone! The ReliaQuest Threat Research team recently provided a wrap up of the most commonly used loaders, the top 80% which comprised of only three different malware! These big three are #QBot, #SocGholish, and #RaspberryRobin. THEN, they not only provided the data sheet to provide to your management or C-suite, they broke them down even further to include technical details as well! Thank you to the Threat Research team for such a great report, I hope you enjoy it as much as I did, and Happy Hunting!

The 3 Malware Loaders Behind 80% of Incidents
reliaquest.com/blog/the-3-malw

#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2023-06-22

ISC Diary: @malware_traffic reviews #Qakbot (#Qbot) from Thurs 2023-06-22, obama271 distribution tag i5c.us/d29968

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst