all InfoSec news
Qakbot-affiliated actors distribute Ransom Night malware despite infrastructure takedown
Oct. 5, 2023, 11:20 a.m. | MalBot
Malware Analysis, News and Indicators - Latest topics malware.news
- The threat actors behind the Qakbot malware have been conducting a campaign since early August 2023 in which they have been distributing Ransom Knight ransomware and the Remcos backdoor via phishing emails.
- Notably, this activity appeared to begin before the FBI seized Qakbot infrastructure in late August and has been ongoing since, indicating the law enforcement operation may not have impacted Qakbot operators’ spam delivery infrastructure but rather only their command and control (C2) servers.
- Talos attributed this new campaign …
august backdoor campaign emails fbi infrastructure malware phishing phishing emails qakbot qakbot malware ransom ransomware remcos seized takedown threat threat actors
More from malware.news / Malware Analysis, News and Indicators - Latest topics
New Redline Version: Uses Lua Bytecode, Propagates Through GitHub
1 day, 6 hours ago |
malware.news
Showcasing Artwork by Max for Autism Awareness Month
1 day, 20 hours ago |
malware.news
Kaiser Permanente notifies 13.4M patients of potential data exposure
1 day, 20 hours ago |
malware.news
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Network Security Engineer
@ Meta | Menlo Park, CA | Remote, US
Security Engineer, Investigations - i3
@ Meta | Washington, DC
Threat Investigator- Security Analyst
@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC
Security Operations Engineer II
@ Microsoft | Redmond, Washington, United States
Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas
@ Goldman Sachs | Dallas, Texas, United States