QakBot

S0650

Malware.View on attack.mitre.org

About this malware

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.

Techniques used71

Procedure examples71

TechniqueProcedure example
T1005
Data from Local System

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.

T1010
Application Window Discovery

QakBot has the ability to enumerate windows on a compromised host.

T1016
System Network Configuration Discovery

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016.001
Internet Connection Discovery

QakBot can measure the download speed on a targeted host.

T1018
Remote System Discovery

QakBot can identify remote systems through the net view command.

T1027
Obfuscated Files or Information

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.

T1027.001
Binary Padding

QakBot can use large file sizes to evade detection.

T1027.002
Software Packing

QakBot can encrypt and pack malicious payloads.

T1027.005
Indicator Removal from Tools

QakBot can make small changes to itself in order to change its checksum and hash value.

T1027.006
HTML Smuggling

QakBot has been delivered in ZIP files via HTML smuggling.

T1027.010
Command Obfuscation

QakBot can use obfuscated and encoded scripts.

T1027.011
Fileless Storage

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1033
System Owner/User Discovery

QakBot can identify the user name on a compromised system.

T1036.008
Masquerade File Type

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1041
Exfiltration Over C2 Channel

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.

View all 71 procedure examples

Groups that use it3

Campaigns0

None recorded.

References4

  1. ATT QakBot April 2021 Open source
    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.
  2. Kaspersky QakBot September 2021 Open source
    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.
  3. Red Canary Qbot Open source
    Rainey, K. (n.d.). Qbot. Retrieved September 27, 2021.
  4. Trend Micro Qakbot December 2020 Open source
    Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.