QakBot
QakBot (also known as Qbot or Pinkslipbot) is a sophisticated malware that originated in 2008 as a banking trojan but evolved into a multi-purpose cybercriminal tool.
Core Capabilities• Financial data theft: Steals banking credentials, credit card details, and personal data through browser cache scanning and keylogging.• Network propagation: Spreads laterally via network shares, PowerShell scripts, and the Mimikatz exploit kit to compromise entire networks.• Modular payload delivery: Acts as a gateway for ransomware (Conti, Black Basta, REvil) and tools like Cobalt Strike or Brute Ratel.• Email hijacking: Harvests email credentials to create convincing phishing threads for further attacks.
Qilin ransomware groupQilin is a Russian-speaking cybercrime organization and ransomware-as-a-service (RaaS) group that first emerged in July/August 2022, initially operating under the name “Agenda” before rebranding as Qilin. The group is known for its sophisticated and aggressive tactics, targeting organizations across multiple sectors—especially healthcare, manufacturing, education, and critical infrastructure—in countries including the UK, US, Canada, France, Japan, Brazil, and others.
Key Features and Tactics
Qilin provides affiliates with customizable ransomware tools and infrastructure, taking a 15–20% cut of ransom payments. The group exfiltrates sensitive data before encrypting systems, then threatens to release the stolen data unless a ransom is paid—sometimes publishing data even if the ransom is paid. Qilin uses kernel-level exploits, process injection, and Bring-Your-Own-Vulnerable-Driver (BYOVD) methods to bypass and disable security controls.
Initial access it typically gained through compromised VPNs, phishing emails, or exploiting vulnerabilities in exposed services (e.g., Fortinet devices). Persistence achieved via scheduled tasks, group policy manipulation, and registry run key modifications.
Notably, Qilin affiliates can tailor ransomware payloads for specific targets, adjust ransom amounts, and control deployment timing.