HomeSecurityQbot botnet uses new infection techniques

Qbot botnet uses new infection techniques

A well-known botnet that first appeared 15 years ago has been detected with new attack techniques. It is the Qakbot or Qbot botnet, which, according to researchers at Sophos Labs, jumps into the middle of active email threads, using compromised accounts of victims whose systems were already affected by the malware.

See also: Qbot and Lokibot target Windows Regsvr32 again

Qakbot Qbot botnet

Cybercriminals have long used variants of Qbot to collect data and conduct reconnaissance within victims' networks illegally.

In a study published Thursday, researchers said the malicious messages that appeared in emailtook the form of a reply-all message. The message contained a short sentence along with a link to download a zip file. That file contained a malicious Office document.

The links may appear as simple URLs or as hotlinked text in the body of the email. Users who open the links and the malicious document become victims of the Qbot botnet.

Researchers Andrew Brandt and Steeve Gaudreault noted that the abilities to mimic a real conversation make it difficult to detect this new attack from the Qbot botnet.

See also: Qbot malware takes only 30 minutes to steal information

The researchers said: “Because the malware is so good at doing this – quoting the original message after its malicious reply – it can be difficult for targets of these attacks to recognize that the messages they receive are not from the actual owner of the email address from which the messages appear to come.”

In one attack, in which Qbot sent an announcement about a music concert, the malware delivered at least three different payloads, including a web injector for stealing credentials and an ARP-scanning component.

Researchers noted that a Qbot infection may be an omen that another more serious attack (e.g. ransomware) is about to occur.

See also: REvil ransomware member extradited to US to stand trial for Kaseya attack

The researchers added: “We encountered samples of the Qakbot (Qbot) botnet that deliver Cobalt Strike beacons directly to the infected computer, providing the botnet operators with a secondary revenue stream: Once the threat actors behind Qbot use the infected computer for their own purposes, they can then sell others access to the compromised network.”

More details can be found in the Sophos report.

Source: Infosecurity Magazine

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS