First appearing on the scene as a banking trojan in 2007, Qbot has since expanded to become a powerful botnet threat that frequently works with ransomware gangs. Now the group can count Black Basta as their latest partner.
Qbot collects user credentials and spreads through networks quickly, before pulling down and running ransomware on infected machines. Delivered threats like Black Basta then disable Microsoft Defender to hinder detection, helping to ensure their success at stealing and encrypting files.
Qbot accounted for 74.3% of malicious payloads in phishing emails during the first quarter of this year. Black Basta came on the scene as recently as April, with 12 attacks in just two weeks and ransom demands as high as $2 million.
The Advanced Email Security pack for Acronis Cyber Protect Cloud keeps malicious payloads out of users' inboxes, while the Active Protection detects and blocks ransomware threats like Black Basta — preventing their execution.