Qbot is a data-stealing and backdoor botnet associated in the provided content with phishing-driven initial access, malware delivery, and follow-on post-compromise tooling. The content states that a group connected to the Qbot botnet used the Follina vulnerability (CVE-2022-30190) in phishing campaigns to infect systems. It also states that Qbot was observed delivering Brute Ratel in 2022. In addition, threat actors affiliated with Qbot were observed using remote monitoring and management tools including Atera and Splashtop, alongside Cobalt Strike, as alternative channels for persistent access. Based on the provided content, Qbot activity includes use of phishing, exploitation of Follina for infection, delivery of commercial post-exploitation tooling, and abuse of legitimate RMM software for persistence. Alias mentioned in the content: qbot.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed delivering the Brute Ratel post-exploitation framework in 2022.
Affiliated threat actors use RMM tools such as Atera and Splashtop, alongside Cobalt Strike, to maintain persistent access in compromised environments.
Operators connected to the Qbot (QakBot) botnet are running phishing campaigns exploiting the Follina (CVE-2022-30190) MSDT RCE to infect systems and deliver malware payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.