#RackspaceOutage Get your playbook out, and inventory the email (looking for sensitive data, PII, and stored passwords in "notes") of the affected users so when you are contacted by the threat actor, you have a clear IDEA of what you are being asked to pay for.
#Dumpulator script to extract decrypted strings from recent #Qakbot payloads.
This works by brute forcing index values to the Qakbot string decryption function.
Hoping to put out a detailed blog soon.
#RE#malware