The FBI’s operation only affected the group’s command and control servers [3], leaving their spam delivery infrastructure intact [2] [3] [4] [5]. The Qakbot malware group [3] [4] [5] [6], originally a banking trojan that evolved into a botnet for ransomware attacks [3], is still active and may choose to rebuild their infrastructure [3] [5]. Since August 2023 [1] [2] [4] [8], researchers from Cisco’s Talos unit have observed the group running a campaign using phishing attacks to distribute the Ransom Knight ransomware and Remcos RAT [3]. In this campaign [1] [5], Qakbot has inserted malicious messages into existing email conversations and downloaded three different malicious payloads [7], including modules for password-stealing [7], network scanning [7], and sending spam emails [7]. The campaign uses LNK files in phishing emails [3], with filenames written in Italian [3], suggesting a focus on users in that region [3].

