Qbot, Lokibot malware switch back to Windows Regsvr32 delivery

Malware distributors have turned to an older trick known as Squiblydoo to spread Qbot and Lokibot via Microsoft Office document using regsvr32.exe. A report from the threat research team at security analytics platform Uptycs shows that the use of regsvr32.exe has been spiking for the past couple of months, occurring via various document formats but mainly Excel files.

Read full article on Bleeping Computer

 


Date:

Categorie(s):

Tag(s):