March 4, 2019 By David Bisson 2 min read

Security researchers spotted a new attack campaign that’s targeting organizations in several countries with a new variant of Qbot banking malware.

In its investigation, Varonis found the campaign consists of phishing emails that come with an attached ZIP file using a .doc.vbs extension. Upon execution, the VBS script extracts information about the target machine’s operating system and attempts to check for strings associated with well-known antivirus software. It then uses the BITSAdmin tool to run a malware loader.

This loader, which has multiple versions signed with different digital certificates, creates a registry value, scheduled task and startup shortcut to establish persistence on the infected machine. It then launches a 32-bit explorer.exe file before injecting the main payload: a new variant of Qbot. This malware is capable of keylogging, stealing credentials/cookies from a web browser and hooking into running processes so it can latch onto users’ banking login information.

Qbot’s Adaptability in Recent Years

Varonis noted that the campaign is mostly targeting corporations located in the U.S., but it also has hit organizations around the world, including companies based in Europe, Asia and South America. Researchers analyzed the threat’s command-and-control (C&C) server and came across evidence suggesting that this Qbot campaign has already claimed thousands of victims.

This isn’t the first time Qbot has gone through some changes. For example, researchers at BAE Systems identified a variant back in April 2016 that incorporated polymorphic code, thereby making itself more difficult to detect. In November 2018, Alibaba Cloud Security uncovered a new version capable of performing brute-force attacks and enlisting infected hosts into a botnet.

How to Defend Against Banking Malware

Security professionals can help defend against banking malware like Qbot by using a unified endpoint management (UEM) platform to set up security policies and compliance rules that automate malware remediation. This step will help streamline the organization’s response capabilities in the event of a malware infection.

Additionally, security professionals should use a sophisticated anti-phishing solution that tracks which brands are under attack and uses machine learning to become proficient in evolving phishing tactics.

More from

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today