As QBot campaigns grow in size and frequency, researchers are looking for ways to break the trojan to combat the threat.

See also: Log4Shell vulnerability: Hackers are already using it for malware attacks
Victims are usually infected with Qbot through another malware infection or through phishing campaigns that use various lures, such as fake invoices, payment and banking information, scanned documents or invoices.
In a new report, Microsoft breaks down the QBot attack chain into its distinct “building blocks,” which can vary depending on the operator using the malware and the type of attack it is carrying out.
To illustrate the attack chain, Microsoft used Lego pieces of different colors, each representing a step in an attack.

These different attack chains are either the result of a highly targeted approach or an attempt to attack a single point of entry, testing multiple attack channels simultaneously.
Even when examining three devices targeted by the same campaign, attackers can use three different attack chains.
For example, Device A eventually suffers a ransomware attack, Device B is used for lateral movement, while Device C is used for credential theft.
See also: QBot trojan replaces IcedID in malspam campaigns!

The use of different attachment chains in the same attack highlights the importance of analyzing all evidence in post-attack investigations, as no safe conclusions can be drawn by examining sample logs or what happened on a single device.
However, whatever happens in the later stages, it is important to emphasize that a QBot attack begins with the sending of an email containing malicious links, attachments, or embedded images.
The messages are usually short and contain a call to action that email security solutions ignore.
After the email is delivered, Qbot attack chains use the following building blocks:
Macro Activation – Every Qbot campaign delivered via email uses malicious macros to deliver the Qbot payload.
Qbot Delivery – Qbot is typically downloaded as an executable file with an .htm or .dat extension and then renamed to non-existent file extensions such as .waGic or .wac. Microsoft notes that in many cases, Qbot delivery involves creating a C:\Datop as described in this article.
Process Injection for Discovery – Qbot payloads are then injected as DLLs into other processes, most commonly MSRA.exe and Mobsync.exe.
See also: Qbot malware has changed and is spreading using a new method
Scheduled Tasks – Creates a scheduled task so that Qbot starts every time Windows restarts and a user logs on to the device.
Credential and browser data theft – Steals credentials from Windows Credential Manager and browser history, passwords, and cookies from installed web browsers.
Email exfiltration – Steals emails from infected devices that attackers use in other chain-reply phishing attacks against employees and business partners.
Additional Payloads, Lateral Traffic, and Ransomware – This block in the attack chain is intended for a variety of different malicious activities and payloads, including deploying Cobalt Strike beacons, lateral network propagation, and ransomware deployment.
