TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

Qakbot Malware Takedown and Defending Forward | Huntress

2023-08-30 · Read original ↗

ATT&CK techniques detected

4 predictions
T1486Data Encrypted for Impact
88%
"qakbot malware takedown and defending forward | huntress on tuesday, august 29, 2023, the federal bureau of investigations los angeles announced that they and other international partners disrupted the qakbot malware infrastructure in a successful takedown. first things first, th…"
T1056.001Keylogging
87%
"as many potential victims as possible. it often lurks in the environment just to maintain persistence, so another threat actor can then obtain the access and consequently deploy ransomware, mine cryptocurrency, disrupt or deface software or any other post - exploitation effects. …"
T1486Data Encrypted for Impact
76%
"activity. ” needless to say, this is a huge win for our industry. we share the same sentiment as other cybersecurity practitioners, researchers, malware analysts and threat hunters in expressing a massive congratulations to law enforcement. this is a day of genuine celebration. t…"
T1055.001Dynamic-link Library Injection
51%
"2022, we started to look for creative ways to limit the effects of qakbot. we would dig into the malware samples, do some reverse engineering and analysis, and consider different techniques that might prevent infection. since threat actors and cybercriminals need to remain stealt…"

Summary

With the FBI's takedown of Qakbot malware, we're sharing how the Huntress team developed our own Qakbot vaccine and our commitment to defend forward.