Identification and Disruption of QakBot Infrastructure
What it means
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Identification and Disruption of QakBot Infrastructure. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Why it matters
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Recommended actions
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Potential operational benefits
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Cybersecurity Advisory Identification and Disruption of QakBot Infrastructure Release Date August 30, 2023 Alert Code AA23-242A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to disseminate QakBot infrastructure indicators of compromise (IOCs) identified through FBI investigations as of August 2023. On August 25, FBI and international partners executed a coordinated operation to disrupt QakBot infrastructure worldwide. Disruption operations targeting QakBot infrastructure resulted in the botnet takeover, which severed the connection between victim computers and QakBot command and control (C2) servers. The FBI is working closely with industry partners to share information about the malware to maximize detection, remediation, and prevention measures for network defenders. CISA and FBI encourage organizations to implement the recommendations in the Mitigations section to reduce the likelihood of QakBot-related activity and promote identification of QakBot-facilitated ransomware and malware infections. Note: The disruption of QakBot infrastructure does not mitigate other previously installed malware or ransomware on victim computers. If potential compromise is detected, administrators should apply the incident response recommendations included in this CSA and report key findings to a local FBI Field Office or CISA at cisa.gov/report . Download the PDF version of this report: AA23-242A Identification and Disruption of QakBot Infrastructure (PDF, 570.50 KB ) For a downloadable copy of IOCs, see: AA23-242A STIX XML (XML, 51.62 KB ) AA23-242A STIX JSON (JSON, 43.12 KB ) TECHNICAL DETAI
Indicatori CISA verificabili
41 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T09:03:05.533317+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| ipv4-addr | 193[.]29[.]187[.]41 | |
| ipv4-addr | 188[.]127[.]243[.]193 | |
| ipv4-addr | 188[.]127[.]243[.]147 | |
| ipv4-addr | 188[.]127[.]243[.]145 | |
| ipv4-addr | 185[.]81[.]114[.]188 | |
| ipv4-addr | 95[.]211[.]250[.]117 | |
| ipv4-addr | 95[.]211[.]250[.]98 | |
| ipv4-addr | 95[.]211[.]250[.]97 | |
| ipv4-addr | 95[.]211[.]198[.]177 | |
| ipv4-addr | 95[.]211[.]172[.]109 | |
| ipv4-addr | 95[.]211[.]172[.]108 | |
| ipv4-addr | 95[.]211[.]172[.]86 | |
| ipv4-addr | 95[.]211[.]172[.]7 | |
| ipv4-addr | 95[.]211[.]172[.]6 | |
| ipv4-addr | 95[.]211[.]95[.]14 | |
| ipv4-addr | 94[.]198[.]53[.]17 | |
| ipv4-addr | 45[.]84[.]224[.]23 | |
| ipv4-addr | 23[.]236[.]181[.]102 | |
| ipv4-addr | 188[.]127[.]243[.]148 | |
| ipv4-addr | 51[.]195[.]49[.]228 | |
| ipv4-addr | 51[.]161[.]202[.]232 | |
| ipv4-addr | 190[.]2[.]143[.]38 | |
| ipv4-addr | 188[.]127[.]242[.]178 | |
| ipv4-addr | 188[.]127[.]242[.]119 | |
| ipv4-addr | 94[.]198[.]51[.]202 | |
| ipv4-addr | 188[.]127[.]243[.]133 | |
| ipv4-addr | 188[.]127[.]243[.]130 | |
| ipv4-addr | 94[.]198[.]50[.]210 | |
| ipv4-addr | 94[.]198[.]50[.]147 | |
| ipv4-addr | 193[.]201[.]9[.]93 | |
| ipv4-addr | 89[.]163[.]212[.]111 | |
| ipv4-addr | 87[.]117[.]247[.]41 | |
| ipv4-addr | 62[.]141[.]42[.]36 | |
| ipv4-addr | 185[.]4[.]67[.]6 | |
| ipv4-addr | 51[.]38[.]62[.]182 | |
| ipv4-addr | 51[.]38[.]62[.]181 | |
| ipv4-addr | 85[.]14[.]243[.]111 | |
| ipv4-addr | 46[.]151[.]30[.]109 | |
| ipv4-addr | 94[.]103[.]85[.]86 | |
| ipv4-addr | 188[.]241[.]58[.]140 | |
| ipv4-addr | 193[.]29[.]187[.]57 |
Provenance
Allegato ufficiale CISA · 2023-08-26T15:47:52Z
SHA-512: e75231106a75902e07cc32507ff11c2cec8ad1407ca1862f8cba4f9d9c0ed4b961547f5a1c5240fbd4e2eb1dad6e2cfc746e33f02238ac9c07fa20dea30b9bc8
- Source
- CISA Cybersecurity Advisories
- Publishing entity
- CISA
- Entity type
- National authority
- Area
- North America · US
- Original language
- en · translation in preparation
- Publication
- 30/08/2023 14:00
- Sharing
- TLP:CLEAR
- MITRE ATT&CK
- T1486, T1555.005, T1566.001
- Classification
- Critical
- Stated country
- US
Action indicated by the source
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Official technical references
- https://www.cisa.gov/sites/default/files/2023-08/aa23-242a-identification-and-disruption-of-qakbot-infrastructure.pdf
- https://www.cisa.gov/sites/default/files/2023-08/AA23-242A.stix_.xml
- https://www.cisa.gov/sites/default/files/2023-08/AA23-242A%20Identification%20and%20Disruption%20of%20Qakbot%20Infrastructure.stix_.json
- https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf
- https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf