ATT&CKReferencesKaspersky QakBot September 2021

Kaspersky QakBot September 2021

Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples36

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareQakBot

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.

T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016.001
Internet Connection Discovery
MalwareQakBot

QakBot can measure the download speed on a targeted host.

T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1041
Exfiltration Over C2 Channel
MalwareQakBot

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.

T1047
Windows Management Instrumentation
MalwareQakBot

QakBot can execute WMI queries to gather information.

T1049
System Network Connections Discovery
MalwareQakBot

QakBot can use netstat to enumerate current network connections.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.007
JavaScript
MalwareQakBot

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1090.002
External Proxy
MalwareQakBot

QakBot has a module that can proxy C2 communications.

T1095
Non-Application Layer Protocol
MalwareQakBot

QakBot has the ability use TCP to send or receive C2 packets.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1124
System Time Discovery
MalwareQakBot

QakBot can identify the system time on a targeted host.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1140
Deobfuscate/Decode Files or Information
MalwareQakBot

QakBot can deobfuscate and re-assemble code strings for execution.

T1185
Browser Session Hijacking
MalwareQakBot

QakBot can use advanced web injects to steal web banking credentials.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1482
Domain Trust Discovery
MalwareQakBot

QakBot can run nltest /domain_trusts /all_trusts for domain trust discovery.

T1497.003
Time Based Checks
MalwareQakBot

The QakBot dropper can delay dropping the payload to evade detection.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1555.003
Credentials from Web Browsers
MalwareQakBot

QakBot has collected usernames and passwords from Firefox and Chrome.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1572
Protocol Tunneling
MalwareQakBot

The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol.

T1573.001
Symmetric Cryptography
MalwareQakBot

QakBot can RC4 encrypt strings in C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.