• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
qakbot threat actors still in action, using ransom knight and

QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

You are here: Home / General Cyber Security News / QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks
October 5, 2023

Irrespective of the disruption to its infrastructure, the threat actors powering the QakBot malware have been linked to an ongoing phishing marketing campaign given that early August 2023 that led to the shipping and delivery of Ransom Knight (aka Cyclops) ransomware and Remcos RAT.

This signifies that “the law enforcement operation might not have impacted Qakbot operators’ spam delivery infrastructure but fairly only their command-and-control (C2) servers,” Cisco Talos researcher Guilherme Venere said in a new report revealed right now.

The activity has been attributed with moderate assurance by the cybersecurity agency to QakBot affiliate marketers. There is no evidence to day that the danger actors have resumed distributing the malware loader itself put up-infrastructure takedown.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

QakBot, also known as QBot and Pinkslipbot, originated as a Windows-dependent banking trojan in 2007 and subsequently designed capabilities to deliver further payloads, together with ransomware. In late August 2023, the notorious malware procedure was dealt a blow as component of an procedure named Duck Hunt.

The newest exercise, which commenced just in advance of the takedown, commences with a destructive LNK file possible dispersed via phishing e-mails that, when released, detonates the an infection and in the long run deploys the Ransom Knight ransomware, a latest rebrand of the Cyclops ransomware-as-a-provider (RaaS) plan.

The ZIP archives that contains the LNK files have also been observed incorporating Excel increase-in (.XLL) documents to propagate the Remcos RAT, which facilitates persistent backdoor accessibility to the endpoints.

Cybersecurity

Some of the file names getting applied in the marketing campaign are created in Italian, which indicates the attackers are focusing on customers in that area.

“Although we have not observed the menace actors distributing Qakbot write-up-infrastructure takedown, we evaluate the malware will likely keep on to pose a major menace going ahead,” Venere claimed.

“Given the operators continue to be energetic, they may pick out to rebuild Qakbot infrastructure to entirely resume their pre-takedown activity.”

Observed this write-up interesting? Stick to us on Twitter  and LinkedIn to study more distinctive content material we post.


Some pieces of this write-up are sourced from:
thehackernews.com

Previous Post: «cisco releases urgent patch to fix critical flaw in emergency Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems
Next Post: Supermicro’s BMC Firmware Found Vulnerable to Multiple Critical Vulnerabilities supermicro's bmc firmware found vulnerable to multiple critical vulnerabilities»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.