Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareQakBot | QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated. |
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1016.001 Internet Connection Discovery |
MalwareQakBot | QakBot can measure the download speed on a targeted host. |
| T1018 Remote System Discovery |
MalwareQakBot | QakBot can identify remote systems through the |
| T1033 System Owner/User Discovery |
MalwareQakBot | QakBot can identify the user name on a compromised system. |
| T1041 Exfiltration Over C2 Channel |
MalwareQakBot | QakBot can send stolen information to C2 nodes including passwords, accounts, and emails. |
| T1047 Windows Management Instrumentation |
MalwareQakBot | QakBot can execute WMI queries to gather information. |
| T1049 System Network Connections Discovery |
MalwareQakBot | QakBot can use |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1056.001 Keylogging |
MalwareQakBot | QakBot can capture keystrokes on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1059.007 JavaScript |
MalwareQakBot | The QakBot web inject module can inject Java Script into web banking pages visited by the victim. |
| T1069.001 Local Groups |
MalwareQakBot | QakBot can use |
| T1071.001 Web Protocols |
MalwareQakBot | QakBot has the ability to use HTTP and HTTPS in communication with C2 servers. |
| T1090.002 External Proxy |
MalwareQakBot | QakBot has a module that can proxy C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareQakBot | QakBot has the ability use TCP to send or receive C2 packets. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1110 Brute Force |
MalwareQakBot | QakBot can conduct brute force attacks to capture credentials. |
| T1114.001 Local Email Collection |
MalwareQakBot | QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns. |
| T1124 System Time Discovery |
MalwareQakBot | QakBot can identify the system time on a targeted host. |
| T1132.001 Standard Encoding |
MalwareQakBot | QakBot can Base64 encode system information sent to C2. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQakBot | QakBot can deobfuscate and re-assemble code strings for execution. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1482 Domain Trust Discovery |
MalwareQakBot | QakBot can run |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1518.001 Security Software Discovery |
MalwareQakBot | QakBot can identify the installed antivirus product on a targeted system. |
| T1539 Steal Web Session Cookie |
MalwareQakBot | QakBot has the ability to capture web session cookies. |
| T1555.003 Credentials from Web Browsers |
MalwareQakBot | QakBot has collected usernames and passwords from Firefox and Chrome. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1572 Protocol Tunneling |
MalwareQakBot | The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol. |
| T1573.001 Symmetric Cryptography |
MalwareQakBot | QakBot can RC4 encrypt strings in C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.