<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Qakbot - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/qakbot/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/qakbot/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 03 May 2023 10:03:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Qakbot - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/qakbot/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CYB Watch – April 2023</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/05/cyb-watch-april-2023/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/05/cyb-watch-april-2023/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Tue, 02 May 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[ESXi attacks]]></category>
		<category><![CDATA[Qakbot]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20389</guid>

					<description><![CDATA[<p>Here are the topics of this newsletter edition: A well-known bot often used for cyber-attacks, the Qakbot The First responder Word FOCUS TECH QAKBOT Initially designed to steal banking credentials, Qakbot has evolved into a more versatile malware with multiple...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/cyb-watch-april-2023/">CYB Watch – April 2023</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Here are the topics of this newsletter edition:</p>
<ul>
<li>A well-known bot often used for cyber-attacks, the <span style="color: #800080;"><strong>Qakbot</strong></span></li>
<li>The <span style="color: #800080;"><strong>First responder Word</strong></span></li>
</ul>
<h2 style="text-align: center;">FOCUS TECH</h2>
<h3 style="text-align: center;">QAKBOT</h3>
<p style="text-align: justify;">Initially designed to <span style="color: #800080;"><strong>steal banking</strong></span> credentials, Qakbot has evolved into a more<span style="color: #800080;"> <strong>versatile malware with multiple uses </strong></span>like stealing data or using it as a trojan to enter within an IT system. Besides, it is highly modulable, which allows actor to add new functionalities easily. Over time, its <span style="color: #800080;"><strong>capabilities</strong></span> have <span style="color: #800080;"><strong>expanded</strong></span> to target various types of sensitive information. This <span style="color: #800080;"><strong>increasingly widespread threat</strong> </span>now affects a broader range of victims and industries, especially in European countries, and is used by well-known actors such as black basta ransomware group.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-20391" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1.png" alt="" width="1576" height="984" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1.png 1576w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1-306x191.png 306w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1-768x480.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture1-1536x959.png 1536w" sizes="(max-width: 1576px) 100vw, 1576px" /></p>
<p style="text-align: justify;">To <span style="color: #800080;"><strong>protect against Qakbot</strong></span>, it&#8217;s important to take a proactive approach to security. Implementing <strong><span style="color: #800080;">various</span> <span style="color: #800080;">measures</span></strong> can help defend against this threat:</p>
<ul>
<li style="text-align: justify;">Consider <span style="color: #800080;"><strong>utilizing an EDR system</strong></span> within your organization to ensure constant monitoring and prompt responses to cyberattacks</li>
<li style="text-align: justify;">Monitor <span style="color: #800080;"><strong>IoCs</strong></span>, verify child processes with <span style="color: #800080;"><strong>Sigma rules</strong></span> and restrict admin access</li>
<li style="text-align: justify;">Train users to <span style="color: #800080;"><strong>recognize phishing emails</strong></span> and <span style="color: #800080;"><strong>avoid clicking on suspicious links</strong></span> or opening attachments from unknown senders, as it is a common infection way. It is also recommended to train on<span style="color: #800080;"> <strong>specific personalized modules</strong> </span>as the phishing techniques get more and more sophisticated</li>
<li style="text-align: justify;">Implement <span style="color: #800080;"><strong>strong, unique passwords</strong></span> for all accounts, and use <span style="color: #800080;"><strong>MFA</strong> </span>for all privileged accesses (mail, VPN, cloud…)</li>
<li style="text-align: justify;"><span style="color: #800080;"><strong>Regularly update operating systems</strong> </span>and software to patch vulnerabilities that could be exploited by Qakbot to spread from a post to another for example.</li>
</ul>
<p>While no single solution can guarantee complete protection from Qakbot, <span style="color: #800080;"><strong style="font-size: revert;">combining these strategies</strong></span><span style="font-size: revert; color: initial;"> will significantly </span><span style="color: #800080;"><strong style="font-size: revert;">reduce the risk of infection</strong></span><span style="font-size: revert; color: initial;"> and help maintain a </span><strong style="font-size: revert; color: initial;"><span style="color: #800080;">secure environment</span></strong>.</p>
<p> </p>
<h2 style="text-align: center;">CERT-W: FROM THE FRONT LINE</h2>
<h3 style="text-align: center;">THE FIRST RESPONDER WORD</h3>
<p><img decoding="async" class="aligncenter size-full wp-image-20393" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2.png" alt="" width="1538" height="976" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2.png 1538w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2-301x191.png 301w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2-61x39.png 61w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2-768x487.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/05/Picture2-1536x975.png 1536w" sizes="(max-width: 1538px) 100vw, 1538px" /></p>



<p style="text-align: center;">SEE YOU NEXT MONTH!!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/cyb-watch-april-2023/">CYB Watch – April 2023</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/05/cyb-watch-april-2023/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
