216.73.217.22

Qbot is Back.Connect

· Published 22/01/2025 09:11 · Modified 22/01/2025 09:46

Export JSON

Essential information

Published
22/01/2025 09:11
Modified
22/01/2025 09:46
Tags
2025-01-22 qakbot qbot quackbot
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 6 malware

Description

, an information stealer active since 2007, has re-emerged after a law enforcement disruption in May 2024. New research reveals connections between , Zloader, and BlackBasta ransomware. A new backConnect malware, likely developed by operators, uses DLL side-loading techniques and RC4 encryption. The malware checks for running copies of itself, uses registry keys for configuration, and communicates system information to its command and control server. Analysis of related files suggests potential use in future ransomware attacks. The report provides IOCs and a YARA rule for detection.

External references