Qakbot operators repeatedly changed their intrusion chains between March and May 2023, using malspam and a rotating set of attachment and container formats including PDF, HTML, ZIP, OneNote, WSF/HTA, and XLL files to deliver the malware. Researchers observed HTML smuggling, obfuscated JavaScript, PowerShell, and DLL-based payload staging in March, followed by ZIP-to-XLL chains that rebuilt payloads from split DAT files and created scheduled tasks for persistence.
By April and May, the malware’s operators had shifted from base64-encoded PowerShell toward hex-encoded XMLHTTP requests delivered through WSF files, and used a OneNote-to-MSI lure posing as a Microsoft Azure installer. Later campaigns added stronger defense evasion, including indirect command execution through conhost.exe, DLL side-loading, and curl-based payload retrieval. Researchers also noted that Pikabot samples seen in mid-May shared similar tradecraft, but said the available evidence did not support attributing both malware families to the same actor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
In May 2023, Qakbot introduced defense-evasion techniques including indirect command execution via conhost.exe and DLL side-loading. The updated chains also used curl-based payload retrieval.
Toward the end of April 2023, Qakbot continued using OneNote files in a chain that embedded an MSI masquerading as a Microsoft Azure installer. The MSI included a self-deleting PowerShell script and launched a hex-encoded WSF stage to download Qakbot.
In April 2023, researchers observed Qakbot replacing a base64-encoded PowerShell stage in WSF files with a hex-encoded XMLHTTP request. This changed the execution flow for chains such as PDF to ZIP to WSF before payload retrieval.
During March 2023, ThreatLabz observed a Qakbot variant using malicious Excel add-ins with the .xll extension as the initial vector. The chain reconstructed the payload from split DAT files and created scheduled tasks to run Qakbot every 10 minutes.
In March 2023, researchers observed Qakbot shifting to PDF and HTML files as initial infection vectors. Campaigns used chains such as PDF to JavaScript to PowerShell and HTML smuggling to ZIP and JavaScript before downloading the payload.
At the start of 2023, Qakbot began spreading through OneNote files as an initial infection vector. This marked an early shift in delivery methods before later changes in March and April.
In December 2021, researchers observed Qakbot spreading through malicious ZIP attachments containing XLSB files with Excel 4.0 XLM macros. The sample downloaded a payload into C:\ProgramData\ as an .OCX file masquerading as a DLL and executed it directly or via regsvr32.exe.
Researchers observed the Chinad malware being delivered after exploitation of Microsoft Internet Explorer vulnerability CVE-2014-6332. The campaign also used FTP-based delivery and targeted Chinese domains.
Researchers identified an exploit kit targeting Chinese domains that delivered the Chinad malware family, apparently focusing on infecting systems in Asia for denial-of-service activity. The malware included components such as notepad.exe, image.png, and pic.jpg.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcenews.sophos.com
Open sourcezscaler.com
Open sourcesublime.security
Open sourcemalwarebytes.com
Open sourcemalwarebytes.com
Open sourceattack.mitre.org
Open sourced3fend.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.