Qakbot-backed phishing emails, distributing Windows shortcut files with potentially malicious content, continue despite the FBI-led Operation Duck Hunt disrupting part of the botnet infrastructure. Cybersecurity researchers suggest only command-and-control servers were impacted while spam delivery infrastructure wasn’t. Phishing emails include Zip archives that, once opened, install the Remcos backdoor and download ransomware like Knight. Qakbot remains affiliated with Knight, but its exact role is unclear.

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called DripDropper.