QakBot Banking Trojan Evolves and Now Takes Over Email Conversations to Spread Malware

Stu Sjouwerman | Mar 23, 2022

QakBot Banking Trojan Evolves and Now Takes Over Email Conversations to Spread MalwareAs if stealing all your credentials, cookies, and email wasn’t bad enough, this new version of QakBot inserts itself into your emails, impersonating you to gain access to more victims.

I’ve covered QakBot before – in fact, just a few months ago where we saw a surge in QakBot’s use jump by 65%. But a new analysis of the most recent version of the banking trojan by security researchers at Sophos details how QakBot has evolved and now wants to spread itself to everyone you know.

Once infected – generally via phishing attack – QakBot accesses the inbox of the victim user and impersonates the compromised account, sending out phishing emails via a Reply to All of all existing email threads. To make the email look more authentic (and as with all Reply to All emails) the original message being replied to is quoted.

Generally, the malicious email content is little more than a brief business message in the recipient native language and a malicious link.

qakbot-english-spam-content

This type of attack is dangerous for two reasons: first the malicious email spreading QakBot is most definitely coming from someone that the recipient is conversing with already (you). And, second, the email thread is a known conversation. The only thing that makes this attack seem out of place is the abrupt “here – look at this document” that should seem out of place. Those employees that undergo continual Security Awareness Training will see a red flag immediately. But, sadly, those users that aren’t taught to be vigilant will likely click the link and further spread QakBot.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.