Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareQakBot | QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells. |
| T1027.002 Software Packing |
MalwareQakBot | QakBot can encrypt and pack malicious payloads. |
| T1027.005 Indicator Removal from Tools |
MalwareQakBot | QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQakBot | QakBot can deobfuscate and re-assemble code strings for execution. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.