Summary:
Researchers discovered that numerous malware families, including AsyncRAT, QuasarRAT, and DCRAT, use OneNote attachments as part of their methods. Qakbot is known for using spam email campaigns to spread itself, and it frequently leverages hijacked email threads to make its communications seem convincing and real. OneNote attachments were first utilised by the well-known malware Qakbot in its spam activities in February 2023.[/subscribe_to_unlock_form]
Summary:
Researchers discovered that numerous malware families, including AsyncRAT, QuasarRAT, and DCRAT, use OneNote attachments as part of their methods. Qakbot is known for using spam email campaigns to spread itself, and it frequently leverages hijacked email threads to make its communications seem convincing and real. OneNote attachments were first utilised by the well-known malware Qakbot in its spam activities in February 2023.[emaillocker id="1283"]
The infection begins with a spam email including a OneNote attachment. This fake message's goal is to get the recipient to double-click it and open the attachment, which launches the Qakbot infection. When a user double-clicks the "Open" button, an embedded ISO file is executed, mounting the ISO file to a virtual drive on the user's computer. A specifically created CHM file is displayed in the mounted drive and can be opened by the user after the ISO file has been installed.

Execution Flow
The CHM file serves as a container for multiple files. When a CHM file is opened, an htm file that was stored inside the container is launched. When the file is run, base64-encoded PowerShell content is executed. Using the wget command, the PowerShell script tries to download the malicious content from the list of hardcoded URLs after it has been run. It then stores the downloaded file in the user's temporary location. The DLL file that was downloaded is the actual Qakbot Malware. The PowerShell script also confirms whether the downloaded file is 100 KB in size or larger. If the prerequisite is satisfied, the script continues by invoking the rundll32.exe command to execute the downloaded file.
When the Qakbot file is executed, it has the ability to steal sensitive data, including login credentials and financial information. Despite its beginnings as a banking trojan, it has since developed into a strong tool for getting initial access to devices and networks. Additionally, Cobalt Strike, Brute Ratel, and other malicious tools that can be used to launch more attacks can be downloaded and installed by Qakbot onto the compromised system.
Threat Profile:

References:
The following reports contain further technical details:
https://blog.cyble.com/2023/04/21/qakbot-malware-continues-to-morph/
[/emaillocker]