Trusted Design

The Return of Qbot

概要

Qbot, also known as Qakbot, is a network-aware worm with backdoor capabilities, primarily designed as a credential harvester. It is an old threat and was well-described by Symantec back in 2009.1 The company later released a whitepaper which described Qbot version 910 in great detail. BAE Systems’ Incident Response team were called in to investigate the ongoing infection and support in containing and remediating the threat. A number of Qbot samples were found within the victim organisation’s network; all samples polymorphic variations of the same Qbot family.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Scattered Spider

Score: 9.40
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1578.002 - Create Cloud Instance
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

Medusa Group

Score: 8.71
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1573.002 - Asymmetric Cryptography
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Kimsuky

Score: 11.86
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1218.010 - Regsvr32
  • T1219.002 - Remote Desktop Software
  • T1587 - Develop Capabilities
MITREへのリンク →

Leviathan

Score: 5.09
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1218.010 - Regsvr32
MITREへのリンク →

Lazarus Group

Score: 5.96
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT32

Score: 5.09
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1218.010 - Regsvr32
MITREへのリンク →

Contagious Interview

Score: 9.11
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1219.002 - Remote Desktop Software
  • T1587 - Develop Capabilities
MITREへのリンク →

Moonstone Sleet

Score: 6.19
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1587 - Develop Capabilities
MITREへのリンク →

Cobalt Group

Score: 5.49
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Storm-0501

Score: 5.67
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

OilRig

Score: 6.37
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Turla

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Wizard Spider

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

APT28

Score: 4.54
Matched TTPs:
  • T1669 - Wi-Fi Networks
MITREへのリンク →

APT38

Score: 3.62
Matched TTPs:
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT37

Score: 3.62
Matched TTPs:
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.75
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1219.002 - Remote Desktop Software
  • T1585.001 - Social Media Accounts
  • T1587 - Develop Capabilities
MITREへのリンク →

Scattered Spider

Score: 0.64
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1585.001 - Social Media Accounts
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Contagious Interview

Score: 0.60
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1585.001 - Social Media Accounts
  • T1587 - Develop Capabilities
MITREへのリンク →

Medusa Group

Score: 0.58
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1585.001 - Social Media Accounts
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る