The return of Qbot
released on 2016-04-12 @ 03:24:03 PM
Qbot, also known as Qakbot, is a network-aware
worm with backdoor capabilities, primarily
designed as a credential harvester. It is an old
threat and was well-described by Symantec back
in 2009.1 The company later released a whitepaper
which described Qbot version 910 in great detail.2
In December 2015, several researchers reported that
websites hosting the Rig Exploit Kit were serving an
updated version of Qbot.3 4 5 Then in January 2016,
over 500 devices at a large public organisation were
infected with Qbot: the worm was back, and it was
both more and less effective. While all versions
of Microsoft Windows the worm touched in the
attack were compromised, a number of Windows
XP machines crashed and failed to restart: despite
its renewed potency, the programmers behind Qbot
hadn’t built their bot to be compatible with older
versions of Windows.