Temporary Advertisements:
Ad
Ad
Ad
[QakBot now targets hospital's]
by eyelock - Monday December 18, 2023 at 03:38 PM
#1
A fresh batch of phishing messages has been detected, spreading the QakBot malware.

https://encrypted-tbn0.gstatic.com/image...p;usqp=CAU

This comes after law enforcement successfully dismantled its command-and-control (C2) network a few months ago. 

Microsoft discovered this low-volume campaign, which started on December 11, 2023, and specifically targeted the hospitality industry.

The targets received a PDF from someone pretending to be an IRS employee.

Inside the PDF, there was a URL that downloaded a digitally signed Windows Installer (.msi) file.

Running the MSI file triggered the activation of QakBot through the execution of an embedded DLL using the 'hvsi' export.

Microsoft stated that the payload was created on the same day the campaign began and it is set up with a version 0x500 that has not been seen before.

QakBot, also known as QBot and Pinkslipbot, was stopped during Operation Duck Hunt when authorities accessed its infrastructure and directed infected computers to download an uninstaller file, rendering the malware useless.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 24 4,458 Yesterday, 04:17 PM
Last Post: krassimiryo
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 34 5,531 Sep 16, 2026, 09:11 AM
Last Post: supervisorpusat
  Breached forums and clones? fda5b 7 3,133 Sep 07, 2026, 04:55 PM
Last Post: ShinyHunters
  Claude Mythos biyukean 7 1,085 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 20,042 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz

Forum Jump:


 Users browsing this forum: