"In addition to the new backConnect malware developed by Qbot operators, research has emerged tying zloader[4] activity to that of the BlackBasta ransomware operation. It is highly likely this new side loading backConnect malware has been or is going to be utilized to further ransomware attacks."
⬇️
"Qbot is Back.Connect"
👇
https://medium.com/walmartglobaltech/qbot-is-back-connect-2d774052369f

#CyberVeille #qbot #malware #BlackBasta

Qbot is Back.Connect - Walmart Global Tech Blog - Medium

QBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active since around 2007. It has historically been known as a banking Trojan, meaning that it steals financial…

Walmart Global Tech Blog

Proofpoint's Daniel Blackford is set to take the stage at Black Hat USA for a talk on law enforcement takedowns.

#OperationEndgame is just one botnet disruption that has made recent headlines. #Emotet, #Qbot, #Lockbit, and #Smokeloader are a few others.

Law enforcement cooperates on takedowns -- but are they effective? Be sure to catch Daniel's talk to examine the data!

Microsoft launches AI chatbot for spies

Air-gapping GPT-4 model on secure network won't prevent it from potentially making things up.

Ars Technica
The SEXi $140 Million Ransom & Parades of Trojans, Cyber News Beat

Its been a chaotic news week for trojans and phishing, but this latest ransom news is crazy! This week in cyber, an eye watering $140 million dollar ransom. Digital credit card skimmers compromising…

Medium

New #Qbot #malware variant uses fake Adobe installer popup for evasion

The misleading popup this campaign spawns “Adobe Setup” installs itself regardless of what you click.

As always be careful what you click and download.

#cybersecurity #security #infosec

https://www.bleepingcomputer.com/news/security/new-qbot-malware-variant-uses-fake-adobe-installer-popup-for-evasion/

New Qbot malware variant uses fake Adobe installer popup for evasion

The developer of Qakbot malware, or someone with access to the source code, seems to be experimenting with new builds as fresh samples have been observed in email campaigns since mid-December.

BleepingComputer

Do #takedowns help stop #cybercriminal activity? 🤔

They do, to a certain extent, according to @recordedfuture's 2023 Adversary Infrastructure Report.

📰 Read story here: https://infosecurity-magazine.com/news/malware-takedowns-cybercrime/

#QakBot #QBot #Emotet #CobaltStrike #RAT #botnet #infostealer

Malware Takedowns Show Progress, But Fight Against Cybercrime Not Over

Law enforcement operations on cybercriminal infrastructure have proven efficient at hindering malware activity but are far from being a silver bullet

Infosecurity Magazine
Qbot malware returns in campaign targeting hospitality industry

The QakBot malware is once again being distributed in phishing campaigns after the botnet was disrupted by law enforcement over the summer.

BleepingComputer

Qakbot Gang Still Active Despite #FBI Takedown 🦆🔫❌

A #Qakbot affiliate is still deploying Ransom Knight #ransomware and the Remcos #backdoor via phishing emails, according to @TalosSecurity. #Qbot

https://www.infosecurity-magazine.com/news/qakbot-gang-still-active-despite/

Qakbot Gang Still Active Despite FBI Takedown

Cisco Talos found new evidence that Qakbot-affiliated actors were still distributing ransomware despite the August FBI takedown of the threat group

Infosecurity Magazine
Qakbot: Behörden nahmen 700.000 Bots vom Netz

Dem BKA, FBI und diversen anderen Behörden gelang es, das Qakbot-Netzwerk zu deaktivieren. Es kam aber zu keinen Verhaftungen der Betreiber.

Tarnkappe.info