Resources & Background Details on FBI Qakbot Malware takedown
August 2023 by Check Point Research (CPR)
The FBI announced this week that it has dismantled Qakbot’s (also referred to as Qbot) multinational cyber hacking and ransomware operation, impacting 700,000 computers around the world – including financial institutions, government contractors and medical device manufacturers. The Qakbot malware infected victims via spam emails with malicious attachments, links and served as a platform for ransomware operators. Once infected, the victims’ computer became part of Qakbot’s larger botnet operation, infecting even more victims. Check Point Research (CPR) published their insight into QBot’s attack methods in 2020.
In operation since 2008 by Eastern European cybercriminals, Qakbot is the most commonly detected malware, with 11% of corporate networks worldwide impacted in 1H’23. Qakbot is a multipurpose malware, akin to a Swiss Army knife, that allows cybercriminals to directly steal data (credentials to financial accounts, payment cards, etc) from PCs, while also serving as an initial access platform to infect victims’ networks with additional malware and ransomware. Qakbot is mostly distributed by phishing emails and is highly adaptive and flexible, allowing it to bypass security measures. It uses file types including OneNote, PDF , HTML, ZIP, LNK and more to infect machines.
Here are some statistics drawn by Check Point Research:
• Since March 2023, Check Point Research has observed a decrease in Qbot attacks worldwide and in the US.
• In the US, the percentage of impacted organizations by Qbot decreased by 62% in August compared to March. In August, the number of impacted organizations by Qbot reached 2.1% while globally it impacted 4.9% of organizations; a 52% decrease compared to March. Moreover, in the last week, there has been a 30% decrease in the % of impacted organizations by Qbot worldwide.
• The most impacted Region by Qbot is Latin America, with 22.3% impacted organizations during 2023, followed by Africa with 22.2% impacted organizations and APAC with 12
• The Education/Research industry has suffered the most in 2023 from Qbot attacks, with 23% impacted organizations. Followed by Government/Military with 18% impacted organizations and Healthcare with 14%.
• So far in 2023, 45% of ransomware attacks were against US-based orgs. Manufacturing, Retail and Software were the most targeted industries by ransomware.
According to Sergey Shykevich, Threat Intelligence Manager at Check Point Research:
“We have been tracking Qakbot for a while and this takedown operation is an important step in disrupting a major cybercrime operation. We applaud the FBI and its partners and will continue to monitor the long term impact with cybercriminals. It remains to be seen whether it was a full takedown or whether the operators will be back – and we urge everyone to continue with phishing awareness campaigns, keep up-to-date with security patches and leverage proper anti-ransomware solutions.”