Qakbot Malware… It’s Back, Nastier Than Ever, and with a BullsEye on Healthcare
[vc_row parallax=”” parallax_image=”” row_type=”row” type=”full_width” anchor=”” in_content_menu=”” content_menu_title=”” content_menu_icon=”” text_align=”left” video=”” video_overlay=”” video_overlay_image=”” video_webm=”” video_mp4=”” video_ogv=”” video_image=”” background_image=”” section_height=”” background_color=”” border_color=”” padding=”” padding_top=”” padding_bottom=”” more_button_label=”” less_button_label=”” button_position=”” color=”” css_animation=”” transition_delay=””][vc_column width=”1/1″][vc_column_text]Be thankful if you haven’t heard the name or encountered Qakbot or Pinkslipbot, which are variants of this malware. It is a particularly nasty and evasive form of malware that is self-propagating. It is known to copy itself on the network and onto removable drives, and while moving laterally is known to mutate making it very difficult to analyze and stop.
Attivo has recently seen an outbreak of Qakbot in the medical industry and is working with several security operations teams to help them be able to detect, analyze, and remove this malware in their networks. With Attivo forensics, security teams are also further empowered with C&C IP addresses so that they can proactively update prevention systems and protect against the exfiltration of data.
This blog provides a brief overview of how Qakbot works in the Kill Chain and how by adding in the Attivo Deception Platform, security operations teams can quickly detect, analyze and remediate against these threats.
Exploring Qakbot in the Kill Chain
Adding Deception to Deceive and Delay Attacker
Attivo Forensics and Threat Intelligence
The Attivo BOTsink Multi-dimension Correlation Engine is able to explode attacks safely within a VM. A port can also be opened to communicate with Command and Control for other threat intelligence such as methods, tools, and intent.
- Automatic BOTsink detection or
- Sample upload to BOTsink for analysis
Organizations with some of the best-in-class prevention system are demonstrating that they cannot reliably stop Qakbot.
- New malware strain is going undetected by signature-based systems
- While moving laterally the malware changes itself making it hard to detect and stop
- The web exploits utilized legitimate looking java scripts and are bypassing security prevention systems.
Deception is playing a critical role in protecting against Qakbot attacks. Not reliant on known signatures or attack patterns, Attivo can deceive the attacker into engaging. Once detected, the attack is analyzed and in-depth reporting provided for quarantining and updating of prevention systems. Some of the core cited customer value is the ability to detect Qakbot during lateral movement. It’s ability to mutate has challenged many operations teams.
- Healthcare Industry Under Attack…
- Deception-based Threat Detection for Healthcare
Free Active Directory Assessment
Get Visibility Into Privilege And Service Account Exposure
For a limited time, Attivo Networks is providing free Active Directory Security Assessments to demonstrate how ADAssessor provides unprecedented and continuous visibility to AD vulnerabilities.
Try Our Endpoint Detection Net (EDN) for Free
FAST AND EASY
Free use offer of our Award-winning security solution to prevent attackers from lateral movement, credential theft, and privilege escalation, fast and easy.
ADSecure 90-Day Free Trial
GET PROTECTION AGAINST UNAUTHORIZED ACCESS TO ACTIVE DIRECTORY
- Hide and deny access to AD objects
- Get alerted on unauthorized queries
- Attack details easily viewable in dashboard
- Your data remains on-premise