A new version of the Qbot malware now activates its persistence mechanism before shutting down infected Windows devices and automatically removes any traces upon system reboot.
Qbot (also known as Qakbot, Quakbot, and Pinkslipbot) is a Windows banking trojan with worm functionality that has been active since at least 2009 and is used to steal banking credentials, personal information , and financial data.

In recent campaigns, Qbot victims were infected by phishing emails that included attached Excel pretending to be DocuSign.
Switching to a quieter persistence mechanism
Since researcher James Quinn says the new version of Qbot was detected on November 24, the malware uses a newer and quieter persistence mechanism that exploits system shutdowns and replays messages to change persistence on infected devices.
This tactic is so successful that some researchers previously believed that the Qbot trojan had completely removed this persistence mechanism.
The trojan will add a registry execution key to infected systems allowing it to start automatically upon system login and will attempt to remove it as soon as the user turns on or “wakes up” the computer to avoid detection by anti-malware solutions or security researchers.
What makes this technique stealthy is the perfect timing used by Qbot developers to insert the key into the Windows.
The malware will only add the Run button before the system goes into sleep mode or shuts down.
Qbot will then attempt to delete the persistence key several times upon restart during activation or login.
However, because the key's value name is randomly generated on each infected system, Qbot will attempt to "delete any run keys with value data that matches its path."
While this method of achieving persistence is new to Qbot, some other malware has used it in the past – such as the banking trojans Gozi and Dridex.
Information source: bleepingcomputer.com
