Cyber risk and advisory programs that identify security gaps and build strategies to address them.
MDR that provides improved detection, 24/7 threat hunting, end-to-end coverage and most of all, complete Response.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Be protected by the best from Day 1.
24/7 Threat Investigation and Response.
Expert hunting, research and content.
Defend brute force attacks, active intrusions and unauthorized scans.
Safeguard endpoints 24/7 by isolating and remediating threats to prevent lateral spread.
Investigation and enhanced threat detection across multi-cloud or hybrid environments.
Configuration escalations, policy and posture management.
Detects malicious insider behavior leveraging Machine Learning models.
Customer testimonials and case studies.
Stories on cyberattacks, customers, employees, and more.
Cyber incident, analyst, and thought leadership reports.
Demonstrations, seminars and presentations on cybersecurity topics.
Information and solution briefs for our services.
MITRE ATT&CK Framework, Cybersecurity Assessment, SOC Calculator & more
eSentire has observed a significant increase (see Figure 1) in Qakbot (Qbot) malware infections through the month of June 2022. Qakbot is an information stealing malware. In observed attacks, threat actors employ HTML smuggling (see Figure 2) and password protected ZIP archives to bypass email-based security detections. User interaction is required for successful malware execution.
Observations of Qakbot are highly concerning as the malware has been observed leading to the delivery of multiple ransomware variants. eSentire is sharing details on these attacks, including indicators of compromise, to increase awareness of this threat across our customers.
Qakbot malware has been in active use since at least 2008. Initially the malware was used to steal victim data, but in recent years it has functioned primarily for reconnaissance and ransomware delivery.
In recently observed attacks, threat actors sent emails containing .Zip archives to potential victims. Email lures commonly relate to employee compensation. It should be noted that some recent incidents have involved email thread hijacking. This is a technique where threat actors respond to previously compromised email threads with malicious content. As the email was previously part of a legitimate conversation, it is much less likely to arouse suspicion.
In the recent cases, the delivered .Zip archive contains a malicious Windows Shortcut (.LNK) file; if interacted with, the .LNK file executes a command to download and execute a Qakbot payload. Successful execution of Qakbot leads to connections to attacker Command-and-Control (C2) servers, downloading additional files to the infected hosts, and performing reconnaissance tasks. eSentire has observed a Qakbot infection rapidly leading to the deployment of Cobalt Strike, a red-team tool commonly used prior to ransomware deployment.
The eSentire Threat Intelligence team assesses with high confidence that this is an ongoing campaign. eSentire Threat Intelligence team assesses with high confidence that infections will continue through July 2022.
Figure 1: Timeline of Qakbot observations
Figure 2: HTML Smuggling Technique
Get notified when there's a new security advisory, and receive the latest news, intel and helpful tools & assets. You can unsubscribe anytime.