Researchers Decrypted Qakbot Banking Trojan's Encrypted Registry Keys

13-Jan-22

Researchers in cybersecurity have deciphered the mechanism used by the versatile Qakbot banking trojan to insert encrypted configuration data into the Windows Registry.

Recently, phishing campaigns have culminated in the distribution of a new loader called SQUIRRELWAFFLE, which serves as a channel for retrieving finalstage payloads like Cobalt Strike and QBot.

Read More…