Windows Follina zero-day now being abused to infect PCs with Qbot malware

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Follina is turning out to be quite a threat for system admins everywhere, as new reports are coming in of the vulnerability being used to distribute infostealers, trojans, and ransomware.

Cybersecurity researchers from Proofpoint found threat actors known as TA570 using the Follina flaw to infect endpoints with Qbot, while NCC Group found it being further abused by Black Basta, a known ransomware group.

Qbot, known also as Qakbot, Quakbot, or Pinkslipbot, is a banking trojan, and infostealer, that’s been in use for more than ten years now. Threat actors looking to distribute the infostealer usually go for a combination of phishing and vulnerability exploiting, tricking people into visiting malicious websites which, through various vulnerabilities, end up downloading the trojan onto the device.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Black Basta emerges

Qbot is capable of dealing plenty of damage, logging keys, exfiltrating cookies, hooking processes, but also acting as a dropper for stage-two viruses, malware, or ransomware. This is exactly the hand that Black Basta is playing.

A relatively new entrant into the ransomware space, Black Basta was observed by NCC Group, using Qbot to move laterally through compromised networks, and deploying its ransomware

The group first appeared in April this year, going straight for the American Dental Association, the publication reminds. It uses double-extortion tactics (stealing and encrypting sensitive data) to force victims into paying the ransom.

Follina, also tracked as CVE-2022-30190, is a flaw found in the Windows Support Diagnostic Tool. It can be abused to remotely run code, by getting programs such as Office Word to bring up the tool from a specially crafted document, when opened. 

Microsoft acknowledged the existence of the flaw and promised it was working on a fix. Until that happens, threat actors are actively using the flaw. Among the confirmed attacks are one against the international Tibetan community, conducted by a known Chinese state-sponsored threat actor called TA413.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Intel Lunar Lake concept
Intel's Panther Lake processors won't arrive until Q1 2026 - corroborates previous delay rumors despite former Intel CEO's promise of 2025 launch