Concise Cyber

Subscribe below for free to get these delivered straight to your inbox

Advertisements
November Threat Intelligence Report: FakeUpdates, Qbot, and Formbook Analysis
Advertisements

A threat intelligence report from late November detailed the most prevalent cyber threats impacting organizations globally. The analysis highlighted the significant activity of the FakeUpdates malware, also known as SocGholish, which utilized compromised websites to distribute malicious payloads. The report also tracked the continued persistence of well-known malware families like Qbot and Formbook.

FakeUpdates Campaign Leverages Compromised Websites

The FakeUpdates malware dropper was identified as a primary threat during this period. Attackers injected malicious JavaScript code into legitimate websites, particularly those based on WordPress. This code presented visitors with a fake browser update prompt. When users clicked to download the supposed update, they received a malicious ZIP file. This campaign served as an initial access vector for various other malware and post-exploitation frameworks.

Qbot and Formbook Maintain Top Malware Positions

The report confirmed that the infostealer Qbot remained a dominant threat. Qbot is designed to steal user data, including banking credentials, browser information, and keystrokes. It often spreads through spam campaigns containing malicious attachments or links. Similarly, Formbook, an infostealer targeting the Windows operating system, was also listed among the top prevalent malwares. Formbook is known for its strong evasion techniques and its function of harvesting credentials from web browsers and collecting screenshots. During this period, the Education and Research sector was the most impacted industry globally.

All articles are written here with the help of AI on the basis of openly available information which cannot be independently verified. We do strive to quote the relevant sources.The intent is only to summarise what is already reported in public forum in our own wordswith no intention to plagarise or copy other person’s work.The publisher has no intent to defame or cause offence to anyone, any person or any organisation at any moment.The publisher assumes no responsibility for any damage or loss caused by making decisions on the basis of whatever is published on cyberconcise.com.You’re advised to do your own checks and balances before making any decision, and owners and publishers at cyberconcise.com cannot be held accountable for its resulting ramifications.If you have any objections, concerns or point out anything factually incorrect, please reach out using the form on https://concisecyber.com/about/

Discover more from Concise Cyber

Subscribe now to keep reading and get access to the full archive.

Continue reading