HomeSecurityEmotet botnet spreads QakBot malware

Emotet botnet spreads QakBot malware

Researchers monitoring the Emotet botnet noticed that the malware began pushing the QakBot banking trojan at an unusually high rate, replacing the TrickBot payload it had been using for years.

Last week, Emotet returned to active service after a five-month hiatus. Starting yesterday, the malspam operation briefly began installing TrickBot on compromised Windows systems.

Things changed today when researchers noticed that Emotet was spreading QakBot. A string in the malware indicates that this trojan is now the chosen partner of the Emotet botnet.

A group of researchers and system administrators who have joined forces to combat Emotet operations, called Cryptolaemus, saw today that the threat actor has replaced the TrickBot distribution across all “epochs”.

Emotet botnet QakBot

An Emotet epoch is a subset of the botnet that operates on a separate infrastructure. There are currently three of them, each with separate servers , distribution methods, and payloads.

Speaking to BleepingComputer, the Cryptolaemus team said they saw QakBot distributed throughout the Emotet botnet, while TrickBot was completely absent.

Security researcher Bom identified a sample of the QakBot (QBot) malware and fed it into the Any.Run interactive analysis tool. The results are available at this link. A list of the command and control (C2) server addresses is available here.

Emotet botnet spreads QakBot malware

Additional analysis by cybercrime intelligence firm Intel 471 revealed that the string identifying this QBot campaign is “partner01,” suggesting a strong connection between Emotet and these threats.

Emotet botnet spreads QakBot malware

However, jumping to conclusions about Emotet and TrickBot not working together is not safe as the relationship between these two operators is not exclusive. The Cryptolaemus team said that changing a payload has happened before and that the original duo is very likely to continue their collaboration.

However, this doesn't happen very often. For example, Emotet started using QakBot last year.

TrickBot and QakBot are the preferred partners for Emotet. All three hackers are part of the same Russian-speaking community and have been interacting for a long time.

It is unclear what QakBot distributes to infected systems, but some victims may fall victim to ransomware.

To stay informed about Emotet's campaigns, you can follow Cryptolaemus' profile on Twitter.

Even though there is a different payload, Emotet still relies on emails to distribute the malware, with the threat being delivered via a malicious document.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS