• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
qakbot linked bc malware adds enhanced dns tunneling and remote access

QakBot-Linked BC Malware Adds Enhanced DNS Tunneling and Remote Access Features

You are here: Home / General Cyber Security News / QakBot-Linked BC Malware Adds Enhanced DNS Tunneling and Remote Access Features
January 23, 2025

Cybersecurity researchers have disclosed details of a new BackConnect (BC) malware that has been developed by threat actors linked to the infamous QakBot loader.

“BackConnect is a common feature or module utilized by threat actors to maintain persistence and perform tasks,” Walmart’s Cyber Intelligence team told The Hacker News. “The BackConnect(s) in use were ‘DarkVNC’ alongside the IcedID BackConnect (KeyHole).”

The company noted that the BC module was found on the same infrastructure that was observed distributing another malware loader called ZLoader, which was recently updated to incorporate a Domain Name System (DNS) tunnel for command-and-control (C2) communications.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

QakBot, also called QBot and Pinkslipbot, suffered a major operational setback in 2023 after its infrastructure was seized as part of a coordinated law enforcement effort named Duck Hunt. Since then, sporadic campaigns have been uncovered propagating the malware.

Originally conceived as a banking trojan, it was later adapted into a loader capable of delivering next-stage payloads onto a target system such as ransomware. A notable feature of the QakBot, alongside IcedID, is its BC module that offers the threat actors the ability to use the host as a proxy, as well as offer a remote-access channel by means of an embedded VNC component.

Walmart’s analysis has revealed that the BC module, besides containing references to old QakBot samples, has been further enhanced and developed to gather system information, more or less acting as an autonomous program to facilitate follow-on exploitation.

“In this case the malware we talk about is a standalone backdoor utilizing BackConnect as a medium to allow a threat actor to have hands on keyboard access,” Walmart said. “This distinction is further pronounced by the fact that this backdoor collects system information.”

The BC malware has also been the subject of an independent analysis by Sophos, which attributed the artifacts to a threat cluster it tracks as STAC5777, which, in turn, overlaps with Storm-1811, a cybercriminal group known for abusing Quick Assist for Black Basta ransomware deployment by posing as tech support personnel.

The British cybersecurity company noted that both STAC5777 and STAC5143 – a threat group with possible ties to FIN7 – have resorted to email bombing and Microsoft Teams vishing to prospective targets and trick them into granting the attackers remote access to their computers via Quick Assist or Teams’s built-in screen sharing to install Python backdoors and Black Basta ransomware.

Cybersecurity

“Both threat actors operated their own Microsoft Office 365 service tenants as part of their attacks and took advantage of a default Microsoft Teams configuration that permits users on external domains to initiate chats or meetings with internal users,” Sophos said.

With Black Basta operators having previously relied on QakBot for deploying the ransomware, the emergence of a new BC module, coupled with the fact that Black Basta has also distributed ZLoader in recent months, paints a picture of a highly interconnected cybercrime ecosystem where the developers behind QakBot are likely supporting the Black Basta team with new tools, Walmart said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cisco fixes critical privilege escalation flaw in meeting management (cvss Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9)
Next Post: New Research: The State of Web Exposure 2025 new research: the state of web exposure 2025»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.