A new QBot malware, dubbed “QakNote”, has been detected since last week, with malicious Microsoft OneNote .one file attachments. These attachments are used to infect systems with the banking trojan, putting unsuspecting users at risk.

Qbot, also known as QakBot, is a malware that started as a banking trojan but evolved into something bigger. It has the ability to infiltrate devices and load additional malware with the aim of stealing data, launching ransomware attacks, etc.
See also: Researcher hacked Toyota's GSPIMS application
Last month, cybercriminals began using OneNote attachments in phishing emails as a replacement for malicious macros in documents . Microsoft disabled macros in July 2022, leaving attackers with limited options to execute code on their victims' devices.
However, cybercriminals have the ability to insert almost any file format into a malicious OneNote document, such as VBS or LNK file attachments. These are then executed when a user double-clicks the embedded attachment in a OneNote notebook(as in the QBot malware distribution campaign).
To motivate users to click on the embedded attachment, it is necessary to use social engineering tactics.
Once launched, embedded attachments can execute commands locally to retrieve and install malware.
See also: Clop ransomware for Linux: Flaw allows file recovery
QakNote: Distribution of QBot malware via Microsoft OneNote
According to a recent report by Sophos, QBot operators have been testing the new delivery technique (OneNote file attachments) since January 31 of this year. The attackers are using OneNote files with an embedded HTML application (HTA file), which is used to retrieve the QBot malware payload.
This change in the distribution of the QBot malware was first reported by Cynet researcher Max Malyutinon January 31, 2023.
A script in the HTA file will use the legitimate curl.exe application to download a DLL file (which is Qbot) to the C:\ProgramData folder. It will then be executed using Rundll32.exe.

The QBot payload enters the Windows Assistive Technology Manager (“AtBroker.exe”) to hide its presence and avoid detection by potential AV tools.
Sophos reports that QBot operators use two distribution methods for these HTA files:
- sending emails with an embedded link to the .one file
- using the “thread injections” method.
The second method is a particularly tricky technique, where QBot malware operators hijack existing email and send a “reply to all” message to participants with a malicious OneNote Notebook file as an attachment.
To make these attacks even more convincing, threat actors use a fake button in the Notebook file that supposedly downloads the document from the cloud, but if clicked, executes the embedded HTA attachment.
See also: Royal Ransomware: Linux version targets VMware ESXi servers
Although this action will display a message to the victim, warning about the dangers of executing attachments, there is always a chance that it will be ignored.
To protect against these types of attacks, Sophos recommends that email block all .one file extensions, as they are not commonly sent as attachments.
QBot is an incredibly dangerous form of malware that can have devastating consequences for businesses if they are not adequately protected against it. By following best practices, such as avoiding suspicious emails and regularly scanning their systems for infections, they will be able to effectively protect themselves from this threat, while also keeping their data safe from prying eyes.
Source: www.bleepingcomputer.com
