JAKARTA - Earlier this year, Kaspersky discovered a spike in Qbot malware targeting corporate users, spreading through malicious spam email campaigns. Where they intercept existing work correspondence and forward malicious PDF attachments to the same email thread.

As of April 4, Kaspersky has found that more than 5.000 emails containing PDF attachments have been received in various countries in English, German, Italian and French, with the campaign continuing.

For your information, Qbot is a well-known banking Trojan that functions as part of a botnet network. This malware is capable of stealing data such as passwords and work correspondence.

In addition, this malware also allows attackers to control infected systems and install ransomware, or other Trojans on other devices in the network.

The malware is distributed via genuine working correspondence from potential victims, which have been stolen by cybercriminals. They then forward an email to all existing participants and usually ask them to open a malicious PDF attachment in various situations.

The contents of the PDF file are images that mimic notifications from Microsoft Office 365 or Microsoft Azure. If a user clicks "Open", a malicious archive will be downloaded to their computer from a remote server (compromised website).

“We recommend that companies remain vigilant because the Qbot malware is extremely dangerous, even though its core functionality has not changed over the last two years. Operators are constantly improving their techniques, adding new and convincing elements of social engineering," said Darya Ivanova, Malware Analyst at Kaspersky in a statement received in Jakarta.

To stay safe, Darya advises you to carefully check for red flags, such as misspelled sender email addresses, suspicious attachments, grammatical errors, and so on.

"In addition, a dedicated cybersecurity solution can help ensure the protection of corporate email security," he added.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)