Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareQakBot | QakBot has the ability to enumerate windows on a compromised host. |
| T1055.012 Process Hollowing |
MalwareQakBot | QakBot can use process hollowing to execute its main payload. |
| T1057 Process Discovery |
MalwareQakBot | QakBot has the ability to check running processes. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1070.004 File Deletion |
MalwareQakBot | QakBot can delete folders and files including overwriting its executable with legitimate programs. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1083 File and Directory Discovery |
MalwareQakBot | QakBot can identify whether it has been run previously on a host by checking for a specified folder. |
| T1106 Native API |
MalwareQakBot | QakBot can use |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQakBot | QakBot can deobfuscate and re-assemble code strings for execution. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1497.001 System Checks |
MalwareQakBot | QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found. |
| T1518.001 Security Software Discovery |
MalwareQakBot | QakBot can identify the installed antivirus product on a targeted system. |
| T1553.002 Code Signing |
MalwareQakBot | QakBot can use signed loaders to evade detection. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.