Multiple incident reports describe Qakbot infections delivered through phishing emails that linked to ZIP archives containing malicious Excel files, often using Excel 4.0 macros to fetch DLL payloads. On compromised Windows systems, the malware executed downloaded DLLs with regsvr32.exe, contacted multiple command-and-control servers, and in some cases used distribution tags such as obama166 and aa. Researchers observed Qakbot storing artifacts on disk, changing persistence behavior compared with earlier variants, and in broader campaigns stealing Outlook credentials, adding Windows Defender exclusions, and using internal email threads to spread further inside organizations.
Follow-on activity showed operators deploying Cobalt Strike and VNC-based remote access, including DarkVNC traffic over TCP 443 and VNC beaconing detected after the initial compromise. In one analyzed case, Cobalt Strike and VNC activity appeared about 17 hours after infection, indicating a second-stage intrusion after Qakbot established foothold. Additional reporting ties these intrusions to hands-on-keyboard actions such as reconnaissance, lateral movement over SMB admin shares, service-based persistence, and preparation for ransomware deployment, while one campaign also reportedly abused PrintNightmare (CVE-2021-34527) for SYSTEM-level execution and may have leveraged ProxyLogon and ProxyShell to help distribute malicious emails in enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2022-03-14, a vulnerable Windows host was infected with Qakbot after a malicious email linked to a ZIP archive containing an Excel spreadsheet whose macro downloaded DLL payloads. The payloads were saved locally and executed via regsvr32.exe.
Microsoft reported that recent Qakbot campaigns used embedded-image phishing lures impersonating Craigslist notifications and abused Craigslist’s legitimate email relay system to send anonymized messages from the craigslist.org domain. The analysis also described related delivery and post-infection building blocks, including Excel 4.0 macro documents, regsvr32-based process injection, scheduled-task persistence, credential theft, and email exfiltration.
Microsoft's Security Update Guide published an advisory for the Windows Print Spooler Remote Code Execution Vulnerability tracked as CVE-2021-34527.
SANS analyzed a Qakbot infection generated on 2020-12-08 in which fake-reply malspam delivered a ZIP archive containing a malicious Excel spreadsheet that downloaded a Qakbot DLL and executed it via Rundll32.exe. The report highlighted behavioral changes from a late-November 2020 update, including a switch from EXE to DLL payloads and new encoded registry persistence under HKCU\SOFTWARE\Microsoft instead of the Run key.
A Cynet report states Quakbot has been active since the end of 2007 as a modular banking trojan.
Cynet reported Quakbot intrusions in which operators used phishing-delivered Excel documents, regsvr32.exe execution, persistence mechanisms, Cobalt Strike, and later-stage exploitation of PrintNightmare to gain SYSTEM-level execution by planting a malicious DLL in the spooler driver path. The report also noted suspected abuse of ProxyLogon and ProxyShell in some enterprise environments.
Secureworks described incidents in which GOLD LAGOON used phishing-delivered Excel 4.0 macros to install Qakbot, which then downloaded Cobalt Strike Beacon for reconnaissance, lateral movement, persistence, and potential ransomware deployment. The report also contrasted a REvil ransomware case with another intrusion contained before ransomware execution.
About 17 hours after the 2022-03-14 Qakbot infection, the host generated Cobalt Strike traffic to 190.123.44[.]113 over port 4444 using runfs[.]icu and VNC beacon traffic to 45.153.241[.]142 over port 443. Security Onion produced ETPRO alerts identifying the VNC activity as VNCStartServer command-and-control beaconing.
A phishing email led to a ZIP archive and malicious Excel spreadsheet that downloaded multiple Qakbot DLLs, executed them with regsvr32.exe, and generated post-infection C2 traffic. The same intrusion also produced DarkVNC traffic to 45.153.241[.]142 over TCP 443, indicating follow-on remote access activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cynet.com
Open sourcesecureworks.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcemalware-traffic-analysis.net
Open sourceisc.sans.edu
Open sourcemicrosoft.com
Open sourcemsrc.microsoft.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.