HP Threat Research Blog HP Wolf Security Threat Insights Report Q2 2023

August 23, 2023 Category: Threat Insights Reports By: HP Wolf Security Comments: 0

HP Wolf Security Threat Insights Report Q2 2023

Welcome to the Q2 2023 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q2 2023.

Key Findings

  • QakBot spam activity surged in Q2, tallying 56 campaigns over the quarter. The malware’s distributors switched between many combinations of file types to infect PCs. The HP Threat Research team identified 18 unique infection chains used by QakBot distributors in Q2, highlighting how capable attackers are quickly permutating their tradecraft to exploit gaps in network defenses.
  • HP Wolf Security stopped a flurry of finance-themed malicious spam campaigns in Q2 spreading remote access trojans (RATs) crypted using a Go crypter called “ShellGo”. The malware was packed twice to evade detection, before running shellcode in memory that disarms Windows security features and launches AsyncRAT. The threat actor used a clever technique to run the RAT in memory through a complex sequence of function calls to .NET libraries. The activity shows how easy it is for threat actors to combine tools to thwart detection and analysis, even those with few resources
  • Aggah continue to evolve their tactics, techniques and procedures (TTPs) to elude detection. Notably, in campaigns in Q2 we saw this threat actor store malicious PowerShell commands in DNS TXT records that were retrieved through nslookup commands.

Read the Report

Download the report: HP Wolf Security Threat Insights Report Q2 2023

Download (PDF)

Read all HP Wolf Security Threat Insights Reports

You can download and read our previous reports here.

About the Author

HP Wolf Security

Recent Posts

2023-08-23T09:03:50+01:00August 23rd, 2023|Threat Insights Reports|