Thứ Hai, Tháng Một 30, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Black Basta Ransomware Hackers Infiltrate Network Through Qakbot to Deploy Brute Ratel C4

17 Tháng Mười, 2022
in Tech
0
Black Basta Ransomware Hackers Infiltrate Network Through Qakbot to Deploy Brute Ratel C4
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

The threat actors behind the line ransomware Black Basta has been observed using the Qakbot trojan to deploy the Brute Ratel C4 framework as a second-stage payload in recent attacks.

Cybersecurity firm Trend Micro says this development marks the first time software nascent adversary simulations are delivered through a Qakbot infection, cybersecurity firm Trend Micro said in a technical analysis published last week.

The intrusion, achieved using a phishing email contains a weaponized link that points to a ZIP archive, further leading to the use of Cobalt Strike for side scrolling.

While these legitimate utilities are designed to conduct penetration testing activities, their ability to provide remote access has made them lucrative tools in the hands of attackers looking for information. stealthy way of probing a compromised environment without attracting attention for long periods of time.

This is compounded by the fact that a cracked version of Brute Ratel C4 began circulating last month on the cybercriminals’ underground, prompting its developer to update its licensing algorithm to make it’s harder to crack.

Qakbot, also known as QBot and QuackBot, is an information stealer and banking trojan known to be active since 2007. But its modular design and ability to act as a downloader have made it an attractive candidate for additional malware removal.

According to Trend Micro, the ZIP file in the email contains an ISO file, which then includes a Qakbot payload fetching LNK file, illustrating the efforts of part of the threat actors to adapt other tactics following Microsoft’s decision block macros by default for documents downloaded from the web.

The Qakbot infection was successful by retrieving Brute Ratel and Cobalt Strike, but not before performing automated reconnaissance via built-in command line tools such as arp, ipconfig, nslookup, netstat and whoami.

However, the attack was halted before the threat agent took any malicious action, although it is suspected that the ultimate goal could be a domain-wide ransomware deployment.

In another string of Qakbot executables discovered by the cybersecurity firm, the ZIP file was distributed through an increasingly popular method known as HTML smuggling, resulting in the execution of Brute Ratel C4 as the second stage. two.

The Qakbot-to-Brute Ratel-to-Cobalt Strike kill chain is linked to the group behind the Black Basta Ransomware, the researchers said. “This is based on the overlapping TTPs and infrastructures observed in the Black Basta attacks.”

The findings coincide with a resurgence of Qakbot attacks in recent months using a variety of techniques such as HTML attachments, DLL sideloading, and email chain hijacking, the last of which entails row collection. email series from successful ProxyLogon attacks against Microsoft Exchange servers.

IcedID agents diversify delivery methods

Qakbot is far from unique access-as-a-service malware that is being increasingly distributed via ISO and other file formats to bypass macro restrictions, for Emotet, IcedID and Bumblebee campaigns all follow the same trajectory.

Palo Alto Networks Unit 42, late September 2022, said it discovered a malicious multi-conspiracy Microsoft Compiled HTML Help (CHM) file being used to distribute the IcedID (aka IcedID) malware. is BokBot).

According to Team Cymru, other prominent distribution methods and infection routes involve the use of password-protected ZIP files containing ISO files, copying Qakbot’s files, with payloads passed through a pay-per-installer service called PrivateLoader.

And, on top of that, Emotet appears to be getting ready for a new set of attacks after a brief three-month hiatus to rework its “systeminfo” module to “improve targeting specific victims.” and distinguish tracking bots from real users,” ESET revealed in a series of tweets.

Jean-Ian Boutin, director of threat research at ESET, told The Hacker News: “We haven’t seen a new wave of spam from Emotet since July. “It’s not clear why.”

“They’ve taken a break a few times before, but never for that long. Perhaps this new module means that they are testing modules and will be back in action in the near future, but of course this is just speculation.”

Related Posts

Previous Post

Download ON1 Photo RAW 2023 Full Crack

Next Post

How to download videos from tik tok with best quality

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
How to download videos from tik tok with best quality

How to download videos from tik tok with best quality

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem