back to article Now Windows Follina zero-day exploited to infect PCs with Qbot

Miscreants are reportedly exploiting the recently disclosed critical Windows Follina zero-day flaw to infect PCs with Qbot, thus aggressively expanding their reach. The bot's operators are also working with the Black Basta gang to spread ransomware in yet another partnership in the underground world of cyber-crime, it is …

  1. Clausewitz4.0 Bronze badge

    Black Bastard? Really?

    Creative, tough...

  2. elsergiovolador Silver badge

    Dancing around

    Enterprises must implement new concepts like zero trust and implement stringent identity governance to know what permissions they have granted to all accounts and to watch for any changes."

    Why not just ditch the Windows altogether and pressure corporations to port their tools to Linux?

    Windows architecture is designed for such groups to thrive. Initially so that the services could easily spy on users, but since operatives are paid so little, they sell the secrets to the underworld.

    1. J. Cook Silver badge

      Re: Dancing around

      Why not just ditch the Windows altogether and pressure corporations to port their tools to Linux?

      I think the best response to that is "nailing jelly to a tree". The costs are... ludacris, and most places can't stomach that bill.

      Also, try re-training users on the subtle UI changes going from windows to even a windows-skinned UI on linux.

      And having to change out all the infrastructure that underpings most medium sized companies. (Active Directory, mainly, but DNS, DHCP, File sharing, etc. Even if you phase it in, it's still a huge undertaking.

  3. SammyB

    Just read the workaround. Instead of just deleting "HKEY_CLASSES_ROOT\ms-msdt" as is recommended in the guidance from MS, I simply renamed it by adding a suffix of _x. Changed the URL as well. Simple enough to do. took less than 1 minute. Less time than to write/edit this comment.

