Security researchers have discovered that hackers are alternating between QBot and IcedID in malspam campaigns. QBot and IcedID are banking trojans that often appear to distribute various ransomware strains as the final payload in an attack.
Earlier this year, researchers observed a malicious email campaign that sent Office documents that distributed the QBot trojan. In February, IcedID was the new malware that originated from URLs used by the QBot (or Qakbot). Brad Duncan from Palo Alto Networks observed the two trojans alternating within the malicious campaigns. Specifically, Duncan noted the following:
“The HTTPS URL generated by the Excel macro ends with /ds/2202.gif which would normally distribute Qakbot, but today it distributed IcedID”.

Security researcher James Quinn of Binary Defense also noticed this tactic, mentioning it in a blog post he shared in March, as the company discovered a new variant of IcedID/BokBot while monitoring a malspam campaign from a QakBot “distributor.”
Read also: Hackers distribute malware using contact forms with Google URLs
IcedID started out as a banking trojan in 2017 and has adapted its functionality to distribute malware. According to researchers, IcedID has previously distributed RansomExx, Maze , and Egregor ransomware. A month and a half later, QBot (aka QakBot)was observed distributing ProLock, Egregor, and DoppelPaymer ransomware.
Malware researcher and reverse engineer reecDeep spotted this change on April 12, highlighting that the malicious campaign relies on updated XLM macros.

As seen in the screenshot above, the malicious Office file appears as a DocuSign to trick users into enabling macro support that delivers the payload to the system. The same trick is seen in the analysis by both Binary Defense and Brad Duncan regarding the malware distributor’s move to IcedID distribution in February 2021.
See also: Qbot malware has changed and is circulating with a new method
Recently, security researchers from threat intelligence firm “Intel 471” published information about EtterSilent, a malicious document creator that is gaining popularity due to its continuous development and ability to bypass many security mechanisms (Windows Defender, AMSI, email services). One feature of this tool is that it can create malicious documents that resemble DocuSign or DigiCert protected files that require user interaction for decryption.

According to Intel 471, several hacking gangs began using EtterSilent services, including IcedID, QakBot, Ursnif, and Trickbot.
Suggestion: Trickbot: New module uses Masscan for local network identification
Speaking to Bleeping Computer about the recent QakBot migration, James Quinn confirmed the campaigns, saying that all evidence points to “a fairly large update to QakBot” accompanied by changed decryption algorithms for the internal configuration.
Information source: bleepingcomputer.com
