TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Flashpoint

Qakbot Takedown: A Brief Victory in the Fight Against Resilient Malware

Ian Gray · 2023-08-30 · Read original ↗

ATT&CK techniques detected

5 predictions
T1584.005Botnet
74%
“groups adapt to avoid further disruption. new malware families also inevitably emerge to fill the gaps left by larger takedowns. for example, bazarloader and zloader rose to prominence as loader malware after the emotet takedown. yet despite their disruptions, resilient botnets o…”
T1584.005Botnet
67%
“, it distributed ransomware such as prolock to extort victims. qakbot has also powered large - scale spam email campaigns and brute force attacks. its worm - like spreading kept it entrenched in infected networks. by providing the backdoor access and distribution channel for othe…”
T1486Data Encrypted for Impact
54%
“qakbot takedown : a brief victory in the fight against resilient malware blogs blog qakbot takedown : a brief victory in the fight against resilient malware prior botnet takedowns like emotet and trickbot have shown that sophisticated malware operations, like qakbot, can often re…”
T1588.001Malware
51%
“, it distributed ransomware such as prolock to extort victims. qakbot has also powered large - scale spam email campaigns and brute force attacks. its worm - like spreading kept it entrenched in infected networks. by providing the backdoor access and distribution channel for othe…”
T1583.005Botnet
31%
“groups adapt to avoid further disruption. new malware families also inevitably emerge to fill the gaps left by larger takedowns. for example, bazarloader and zloader rose to prominence as loader malware after the emotet takedown. yet despite their disruptions, resilient botnets o…”

Summary

Prior botnet takedowns like Emotet and TrickBot have shown that sophisticated malware operations, like Qakbot, can often rebuild infrastructure and return from disruptions in new forms

The post Qakbot Takedown: A Brief Victory in the Fight Against Resilient Malware appeared first on Flashpoint.