Loading…

QakBot Trojan Detector

ArcSight
Register   or Login

Description:
The goal of QakBot Trojan Detector is to detect and stop the spread of QakBot trojan. According to X-Force research, QakBot is financial malware known to target businesses to drain their online banking accounts. The malware features worm capabilities to self-replicate through shared drives and removable media. It uses powerful information-stealing features to spy on users’ banking activity and eventually defraud them of large sums of money. The latest version is equipped with the ability to hide from antivirus programs and disable them on endpoints. All this makes QakBot a dangerous tool for targeted attacks on companies, and detecting it at an early stage of the attack can prevent both theft of valuable data and AD lockouts.   Though well-known and familiar from previous online fraud attacks, QakBot continually evolves. This is the first time IBM X-Force has seen the malware cause AD lockouts in affected organizational networks. Source: https://securityintelligence.com/qakbot-banking-trojan-causes-massive-active-directory-lockouts/
Other integrations: