This password-stealing malware just evolved a new tactic to remain hidden
#1
Quote:A well-known form of malware which has been stealing login credentials and finances from enterprises for over a decade has once again been updated with new tricks to make it more effective at avoiding detection.

Qakbot - also known as Qbot -  has been afflicting businesses since 2008, using worm-like capabilities to spread. The information-stealing trojan malware targets Microsoft Windows systems in an effort to create backdoors and make off with the usernames and passwords which can provide access to financial data.
 
Now Qakbot has been updated with a new persistence mechanism which makes it harder for victims to detect and remove the malware. The new obfuscation technique has been detailed by cybersecurity researchers at Cisco Talos.

Victims of the malware are usually infected via a dropper which, when successfully installed, will create a scheduled task on the infected machine that instructs it to execute a JavaScript downloader from one of a number of attacker-controlled malicious domains.

SOURCE: https://www.zdnet.com/article/this-passw...in-hidden/
[-] The following 3 users say Thank You to silversurfer for this post:
  • dinosaur07, harlan4096, ismail
Reply


Messages In This Thread
This password-stealing malware just evolved a new tactic to remain hidden - by silversurfer - 03 May 19, 18:54

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD releases ROCm 6.4, official RDNA4 su...
AMD ROCm 6.4 relea...harlan4096 — 10:05
Best Linux distros for reviving an old P...
Installing the rig...harlan4096 — 10:04
AhnLab, Inc.
AhnLab, Inc. Compute...jasonX — 09:58
QOwnNotes 19.1.6
25.4.0 All TODO...Kool — 16:06
YouTube updates Shorts view count metho...
This is a smart and ...Kiran78 — 11:41

[-]
Birthdays
Today's Birthdays
avatar (45)Rodneykak
avatar (48)tradeSmode
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (45)MeighGoask
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
avatar (42)cdoubapKit
avatar (37)lystraPonia
avatar (30)smith8395john
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>