Tag: QakBot Malware

Microsoft fixes Windows zero-day exploited in QakBot malware attacks
News

Microsoft fixes Windows zero-day exploited in QakBot malware attacks

A zero-day vulnerability that was used in campaigns to install QakBot and other malware payloads on susceptible Windows systems has been patched by Microsoft. This privilege escalation flaw, tracked as CVE-2024-30051, is brought on by a heap-based buffer overflow in the core library of the Desktop Window Manager (DWM). After an attack is successful, the attacker can obtain SYSTEM privileges. When generating graphical user interface features like glass window frames and 3D transition animations, the OS can employ hardware acceleration thanks to the Desktop Window Manager Windows service, which was first released in Windows Vista. While looking into another Windows DWM Core Library privilege escalation problem, tracked as CVE-2023-36033 and also used as a zero-day in attacks, Kaspe...
QakBot Malware Resurfaces with New Tactics Targeting the Hospitality Industry
News

QakBot Malware Resurfaces with New Tactics Targeting the Hospitality Industry

More than three months after the QakBot malware was deconstructed through an infiltration of its command-and-control (C2) network as part of an enforcement operation, a fresh wave of phishing messages propagating the malware has been noticed. The finding was made by Microsoft, which identified it as a low-volume campaign that started on December 11, 2023, and was directed towards the hospitality sector. Targets stated in a series of tweets made on X (previously Twitter) that it had received a PDF from a user posing as an IRS employee. A URL to download a digitally signed Windows Installer (.msi) was included in the PDF. Qakbot was called through export read more QakBot Malware Resurfaces with New Tactics Targeting the Hospitality Industry. Get up to date on the latest cybersecuri...
FBI Dismantles QakBot Malware,Frees 700,000 Computers, Seizes $8.6 Million
News

FBI Dismantles QakBot Malware,Frees 700,000 Computers, Seizes $8.6 Million

The notorious Windows malware family QakBot, which is thought to have infected over 700,000 machines worldwide and enabled financial theft and ransomware, was brought down by a concerted law enforcement operation known as Operation Duck Hunt. In order to accomplish this, the U.S. Justice Department (DoJ) claimed that the virus is "being deleted from victim computers, preventing it from doing any more harm," and that it also seized more than $8.6 million in cryptocurrencies in illegal gains. In addition to providing technical support, the cybersecurity firm Zscaler, the cross-border exercise included France, Germany, Latvia, Romania, the Netherlands, the United Kingdom, and the United States read more FBI Dismantles QakBot Malware Frees 700000 Computers Seizes $8.6 Million. Stay i...
QakBot Malware Operators Expand C2 Network with 15 New Servers
News

QakBot Malware Operators Expand C2 Network with 15 New Servers

By the end of June 2023, the QakBot (also known as QBot) malware's handlers had installed 15 new command-and-control (C2) servers. The results, which come a little over two months after Lumen Black Lotus Labs reported that 25% of its C2 servers are only active for a single day, are a continuation of Team Cymru's examination of the malware's infrastructure. "QakBot has a history of taking an extended break each summer before returning sometime in September, with this year's spamming activities ceasing around 22 June 2023," the cybersecurity company claimed read more QakBot Malware Operators Expand C2 Network with 15 New Servers. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and...