Hunting Qakbot

No ratings

Presented at BlueHat 2023 by

When it comes to attack surfaces, there are few quite as large as that of NHS England’s Microsoft Defender for Endpoint estate. With close to 1.7 million endpoints enrolled in a tenant, spanning thousands of separate organizations across the healthcare service, it presents a uniquely challenging environment to protect – one where cyber incidents can have very real, human consequences. How then do we go about defending an IT estate as large and complex as this one? It's a challenge that couldn’t be better illustrated than with the perpetual battle against Qakbot. With delivery mechanisms and TTPs that shift week to week, a repertoire ranging from access-for-sale to the deployment of ransomware and no scruples about targeting healthcare organizations from its operators, Qakbot truly is a formidable adversary. In this talk, Dan Taylor and Ben Magee from NHS England walk through: • A brief overview of the NHS and the role NHS Digital CSOC plays in its defense • The scale of the challenges facing security teams tasked with securing the NHS against the likes of Qakbot, and why common malware poses such an acute threat • The critical role threat hunting (and intelligence) plays in that defense, with technical breakdowns of Qakbot TTPs, the methods we use to stay ahead of them, and the key advantages afforded by Microsoft Defender for Endpoint • Examples of the mistakes, successes, close calls, and critical lessons learned in the interminable battle against Qakbot and its contemporaries