Trusted Design

Threat Spotlight: The Return of Qakbot Malware

概要

Qakbot has been around for years, but it’s nothing to be complacent about. This malware is well-known for its ability to steal credentials and quickly spread through an enterprise over network shares. Given its age, it might seem logical that security controls would have this threat on lockdown. However, the occasional functional enhancements combined with its multiple layers of obfuscation and server-side polymorphism periodically breathe new life into this seemingly immortal malware.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Fox Kitten

Score: 5.15
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Volt Typhoon

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

APT38

Score: 5.68
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

Scattered Spider

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

Moonstone Sleet

Score: 5.68
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

Chimera

Score: 7.55
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
MITREへのリンク →

Lazarus Group

Score: 10.16
Matched TTPs:
  • T1574.013 - KernelCallbackTable
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Sidewinder

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

APT28

Score: 10.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1669 - Wi-Fi Networks
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Threat Group-3390

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Sandworm Team

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

APT29

Score: 4.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

BlackTech

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Patchwork

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Cobalt Group

Score: 6.10
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Mustang Panda

Score: 8.78
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Sea Turtle

Score: 4.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Tropic Trooper

Score: 6.91
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
MITREへのリンク →

APT41

Score: 3.89
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1569.002 - Service Execution
MITREへのリンク →

APT32

Score: 8.42
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

OilRig

Score: 11.01
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

MuddyWater

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Velvet Ant

Score: 11.94
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Medusa Group

Score: 7.01
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
MITREへのリンク →

FIN6

Score: 7.01
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
MITREへのリンク →

FIN8

Score: 7.76
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.010 - Command Obfuscation
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Turla

Score: 8.15
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1027.010 - Command Obfuscation
  • T1078.003 - Local Accounts
MITREへのリンク →

Wizard Spider

Score: 11.04
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1027.010 - Command Obfuscation
  • T1588.003 - Code Signing Certificates
  • T1569.002 - Service Execution
MITREへのリンク →

Kimsuky

Score: 7.68
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1588.003 - Code Signing Certificates
  • T1078.003 - Local Accounts
MITREへのリンク →

Play

Score: 4.53
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1078.003 - Local Accounts
MITREへのリンク →

Silence

Score: 4.26
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
MITREへのリンク →

FIN7

Score: 6.93
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1569.002 - Service Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Velvet Ant

Score: 0.82
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1569.002 - Service Execution
  • T1078.003 - Local Accounts
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Wizard Spider

Score: 0.75
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1588.003 - Code Signing Certificates
  • T1555.004 - Windows Credential Manager
  • T1569.002 - Service Execution
MITREへのリンク →

OilRig

Score: 0.71
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1573.002 - Asymmetric Cryptography
  • T1203 - Exploitation for Client Execution
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

APT28

Score: 0.70
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1669 - Wi-Fi Networks
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 0.65
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1203 - Exploitation for Client Execution
  • T1574.013 - KernelCallbackTable
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1588.003 - Code Signing Certificates
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Turla

Score: 0.62
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1078.003 - Local Accounts
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

APT32

Score: 0.59
Matched TTPs:
  • T1027.010 - Command Obfuscation
  • T1078.003 - Local Accounts
  • T1203 - Exploitation for Client Execution
  • T1569.002 - Service Execution
MITREへのリンク →

FIN8

Score: 0.57
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1027.010 - Command Obfuscation
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る