ATT&CKReferencesKroll Qakbot June 2020

Kroll Qakbot June 2020

Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1074.001
Local Data Staging
MalwareQakBot

QakBot has stored stolen emails and other data into new folders prior to exfiltration.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.