home.social

#qakbot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #qakbot, aggregated by home.social.

fetched live
  1. 🔥 Operation Endgame is BACK! This time targeting #BumbleBee, #Latrodectus, #DanaBot, #WarmCookie, #Qakbot and #Trickbot!

    Once again this is a HUGE win, with a truly international effort! 💪

    As with phase one of #OperationEndgame, Spamhaus are providing remediation support - those affected will be contacted in due course with steps to take.

    For more information, read our write-up here:
    👉 spamhaus.org/resource-hub/malw

  2. UPDATE: DOJ has now published a press release announcing the indictment of RUSTAM RAFAILEVICH GALLYAMOV, aka "Cortes" and other aliases.

    Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme:

    justice.gov/opa/pr/leader-qakb

    ------------ Prior post:

    Clever teasing by #OperationEndgame

    A new vid about Qakbot, "My Happy Lie by Cortes" and they reset the countdown timer to 16 hours while linking to a DOJ press release dated today that has not yet been released:

    "Russian national and leader of Qakbot malware conspiracy indicted in long-running global ransomware scheme"

    #qakbot #malware

  3. I wish every one of you to find someone who loves you like usernamegg loves #QakBot

  4. Трендовые уязвимости мая: лингвистический лесоруб и таинственный файл на ломаном английском

    Хабр, привет! Уже по традиции я, Александр Леонов, ведущий эксперт лаборатории PT Expert Security Center, рассказываю про трендовые уязвимости месяца. Всего их было четыре: 1️⃣ уязвимость, приводящая к удаленному выполнения кода в многоплатформенном опенсорсном инструменте для сбора и обработки журналов Fluent Bit (CVE-2024-4323); 2️⃣ уязвимость, приводящая к удаленному выполнения кода в корпоративной веб-вики Confluence (CVE-2024-21683); уязвимости Microsoft, связанные с 3️⃣ обходом функций безопасности в Windows MSHTML Platform (CVE-2024-30040) и 4️⃣ повышением привилегий в Windows DWM Core Library (CVE-2024-30051). Узнать самые опасные уязвимости мая

    habr.com/ru/companies/pt/artic

    #трендовые_уязвимости #cve #vulnerability_management #microsoft #эксплойт #confluence #dwm #qakbot #ole #патчи

  5. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  6. Cybercriminals are using #Scalable_Vector_Graphics (#SVG) files to deliver malware because SVG is an XML-based vector image format for two-dimensional graphics that supports interactivity and animation. SVG files can natively contain #JavaScript code, which can be executed by browsers when the SVG is loaded.
    They do this by leveraging the #AutoSmuggle tool introduced in May 2022. This tool embeds malicious files into SVG/HTML content, bypassing security measures. Notably, SVG files were exploited to distribute #ransomware in 2015 and the #Ursnif malware in January 2017. A significant advancement occurred in 2022, with malware like #QakBot being delivered through SVG files containing embedded .zip archives. AutoSmuggle campaigns in December 2023 and January 2024 delivered the #XWorm #RAT and #Agent_Tesla #Keylogger, respectively, showcasing a shift towards embedding executable files directly within SVG files to evade detection by Secure Email Gateways (#SEGs). This evolution underscores the need for updated security measures to combat sophisticated malware delivery methods.
    The misuse of SVG files for malware distribution dates back to 2015, with ransomware being one of the first to be delivered through this vector.
    Original report: Cofense

  7. The good news is that these samples are all consistently caught and stopped in Sophos products with our existing endpoint detection rules.

    The Evade_34b (mem/prchollow-b) detections in Sophos Endpoint trigger as soon as Qakbot tries to perform the initial process injection.

    Qakbot has only trickled out a few samples, but the botnet was so large at one point, and so omnipresent, that any activity by threat actors to bring it back deserves surveillance and scrutiny. X-Ops analysts will continue to keep a close eye on any new developments.
    10/10
    #Qakbot #malware #spam

  8. One final curiosity we observed: When run under Windows, the #Qakbot malware spawned a small popup box that makes it appear something called Adobe Setup was running. On some test systems, the Qakbot DLL drops a copy of itself named Adobe.dll.

    If the user clicks the X in the small dialog, the malware spawns a dialog that says "Are you sure you want to cancel Adobe installation?"

    The #malware installs without regard to what you click.
    9/

  9. Prior generations of #Qakbot added, then later removed, the ability to detect whether the malware was running inside a virtual machine. This generation has brought back those checks, and will enter an infinite loop if it finds itself in a VM.

    It also places a duplicate copy of the malware in the user's %TEMP% folder with an 8-random-character filename.
    8/
    #malware #spam