• 🌙 Community Spirit

    Ramadan Mubarak! To honor this month, Crax has paused NSFW categories. Wishing you peace and growth!

QuantumBuilder (APT) groups Agent Tesla, RedLine Stealer, and IcedID (1 Viewer)

Currently reading:
 QuantumBuilder (APT) groups Agent Tesla, RedLine Stealer, and IcedID (1 Viewer)

Recently searched:

osinator

Member
LV
0
Joined
Nov 5, 2025
Threads
2
Likes
1
Awards
1
Credits
1,133©
Cash
0$


Link: Download

Quantom builder

Quantum Builder is a tool sold on the dark web that allows hackers to create malicious Windows shortcut files and other payloads to deliver malware, such as the Agent Tesla remote access trojan (RAT). It enables cybercriminals to execute sophisticated attacks by using techniques like user account control bypass and in-memory PowerShell scripts to evade detection.

Malware Delivery Mechanism​

  • File Types: Generates .lnk, .hta, and ISO payloads.
  • Infection Chain: Typically starts with a spear-phishing email containing a compressed file (like a GZIP or ZIP archive) that includes the malicious shortcut.
  • Execution Process: When the shortcut is executed, it runs embedded PowerShell scripts that can download and execute the final payload from a remote server.

Evasion Techniques​

  • User Account Control (UAC) Bypass: Uses the Microsoft Connection Manager Profile Installer (CMSTP) to execute malware with administrative privileges.
  • Living Off the Land Binaries (LOLBins): Utilizes legitimate Windows tools to evade detection.
  • Regular Updates: The developers frequently update the tool to enhance its evasion techniques and capabilities.


 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips
Recently searched:

Similar threads

Users who are viewing this thread

Top Bottom