Saturday , September 7 2024

New QBot email attacks use PDF and WSF combo to install malware

QBot malware is now distributed in phishing campaigns utilizing PDFs and Windows Script Files (WSF) to infect Windows devices.

Qbot (aka QakBot) is a former banking trojan that evolved into malware that provides initial access to corporate networks for other threat actors. This initial access is done by dropping additional payloads, such as Cobalt StrikeBrute Ratel, and other malware that allows other threat actors to access the compromised device.

Cisco released security updates for two critical security flaws

CISCO released security updates for two critical security flaws impacting its smart Licensing Utility that could allow unauthenticated, remote attackers...
Read More
Cisco released security updates for two critical security flaws

OpenBAS: Cutting-edge breach and attack simulation platform

OpenBAS is a platform that helps organizations to plan, schedule, and conduct crisis exercises, adversary simulations, and breach simulations. OpenBAS...
Read More
OpenBAS: Cutting-edge breach and attack simulation platform

Critical Security Flaws Patched in Zyxel Networking Devices

Zyxel has released software updates to fix a serious security issue in certain access point (AP) and security router versions....
Read More
Critical Security Flaws Patched in Zyxel Networking Devices

CVE-2024-38811: CEV In VMware Fusion Unveiled

VMware released a security advisory for a major vulnerability in the VMware Fusion product. This vulnerability could be exploited by...
Read More
CVE-2024-38811: CEV In VMware Fusion Unveiled

CERT-IN Warns Vulnerabilities in Palo Alto Networks applications

Indian Computer Emergency Response Team (CERT-IN) issued advisories about multiple vulnerabilities in various Palo Alto Networks applications. Attackers could exploit...
Read More
CERT-IN Warns Vulnerabilities in Palo Alto Networks applications

How Malaysia’s Data Centre Industry Poised for Growth

Malaysia is quickly becoming a leading choice for investing in data centers. It aims to generate RM3.6 billion (US$781 million)...
Read More
How Malaysia’s Data Centre Industry Poised for Growth

RansomHub exfiltrated data over 210 victims: US alert

US authorities have issued a cybersecurity advisory about a ransomware group called RansomHub. The group is thought to have stolen data...
Read More
RansomHub exfiltrated data over 210 victims: US alert

Godzilla Fileless Backdoor Exploits Atlassian Confluence flaw

There is a new way to attack Atlassian Confluence using the vulnerability CVE-2023-22527. The Confluence Data Center and Server products...
Read More
Godzilla Fileless Backdoor Exploits Atlassian Confluence flaw

New Cicada ransomware targets VMware ESXi servers

The Cicada3301 ransomware is made in Rust and attacks Windows and Linux/ESXi hosts. Truesec researchers examined a version that targets...
Read More
New Cicada ransomware targets VMware ESXi servers

Monday hits two UK bank apps causes outages

Lloyds Bank and Virgin Money's internet banking services were down on Monday, causing trouble for users to access and view...
Read More
Monday hits two UK bank apps causes outages
Using this access, the threat actors spread laterally through a network, stealing data and eventually deploying ransomware in extortion attacks.

Starting this month, security researcher ProxyLife and the Cryptolaemus group have been chronicling Qbot’s use of a new email distribution method — PDF attachments that download Windows Script Files to install Qbot on victim’s devices.

It starts with an email

QBot is currently being distributed through reply-chain phishing emails, when threat actors use stolen email exchanges and then reply to them with links to malware or malicious attachments.

The use of reply-chain emails is an attempt to make a phishing email less suspicious as its a reply to an ongoing conversation.

The phishing emails use a variety of languages, marking this as a worldwide malware distribution campaign.

QBot phishing email
QBot phishing email
Source: BleepingComputer

Attached to these emails is a PDF file named ‘CancelationLetter-[number].pdf ,’ that, when opened, displays a message stating, “This document contains protected files, to display them, click on the “open” button.”

However, when the button is clicked, a ZIP file that contains a Windows Script (wsf) file will be downloaded instead.

PDF document used to distribute malicious WSF files
PDF document used to distribute malicious WSF files
Source: BleepingComputer

A Windows Script File ends with a .wsf extension and can contain a mixture of JScript and VBScript code that is executed when the file is double-clicked.

The WSF file used in the QBot malware distribution campaign is heavily obfuscated, with the ultimate goal of executing a PowerShell script on the computer.

Malicious WSF file distributed by QBot PDF files
Malicious WSF file distributed by QBot PDF files
Source: BleepingComputer

The PowerShell script that is executed by the WSF file attempts to download a DLL from a list of URLs. Each URL is tried until the file is successfully downloaded to the %TEMP% folder and executed.

PowerShell script executed by the WSF file
PowerShell script executed by the WSF file
Source: BleepingComputer

When the QBot DLL is executed, it will run the PING command to determine if there is an internet connection. The malware will then inject itself into the legitimate Windows wermgr.exe (Windows Error Manager) program, where it will quietly run in the background.

QBot malware injected into the memory of the Wermgr.exe process
QBot malware injected into the memory of the Wermgr.exe process
Source: BleepingComputer

QBot malware infections can lead to devastating attacks on corporate networks, making it vital to understand how the malware is being distributed.

Ransomware affiliates linked to multiple Ransomware-as-a-Service (RaaS) operations, including BlackBasta, REvil, PwndLocker, EgregorProLock, and MegaCortex, have used Qbot for initial access into corporate networks.

Researchers at The DFIR Report have shown that it only takes around 30 minutes for QBot to steal sensitive data after the initial infection. Even worse, malicious activity only takes an hour to spread to adjacent workstations.

Therefore, if a device becomes infected with QBot, it is critical to take the system offline as soon as possible and perform a complete evaluation of the network for unusual behavior.

Check Also

Chart

Minecraft Server faced 3.15 Billion Packet Rate DDoS Attack

Global Secure Layer (GSL) recently mitigated a huge volume of DDoS attack ever recorded. The …

Leave a Reply

Your email address will not be published. Required fields are marked *