ATT&CKReferencesATT QakBot April 2021

ATT QakBot April 2021

Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareQakBot

QakBot has the ability to enumerate windows on a compromised host.

T1055.012
Process Hollowing
MalwareQakBot

QakBot can use process hollowing to execute its main payload.

T1057
Process Discovery
MalwareQakBot

QakBot has the ability to check running processes.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1083
File and Directory Discovery
MalwareQakBot

QakBot can identify whether it has been run previously on a host by checking for a specified folder.

T1106
Native API
MalwareQakBot

QakBot can use GetProcAddress to help delete malicious strings from memory.

T1140
Deobfuscate/Decode Files or Information
MalwareQakBot

QakBot can deobfuscate and re-assemble code strings for execution.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1553.002
Code Signing
MalwareQakBot

QakBot can use signed loaders to evade detection.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.