Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Patient Zero Day current page
Link copied

Patient Zero Day

Oct 20, 2017
Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Blog banner default
Patient Zero Day
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

Hospitals are used to dealing with viruses, from the common cold to a variety of tropical diseases there are procedures in place to diagnose, isolate and treat patients. What is more challenging to them is dealing with digital infections, which can wreak havoc and cause the digital realm to endanger people’s lives.

Recently Melbourne Health’s networks were infected by a new variant of the Qbot malware strain. This slightly obscure malware also known as Qakbot has been used by Russian hackers since 2009 and specialises in infecting older machines using unknown or unpatched flaws. In this case Melbourne Health’s older Windows XP machines seem to be patient zero in the outbreak. As any doctor will tell you an aging population and new virus strains from abroad is a pandemic waiting to happen.

The health sector are not the only ones keeping Windows XP on life support, the British Navy still rely on Windows XP for their fleet of nuclear submarines. In an unfortunate twist for Melbourne Health, the Qbot malware, although entering by a zero day XP exploit, was actually built to target Windows 7 causing the unfortunate side effect of disabling infected XP systems.

In our malware labs we have recently encountered several compromised websites delivering Qbot via the Rig Exploit Kit. These attacks have been using either a known Flash exploit or an unknown IE exploit to download and run the Qbot malware on the victim's machine. Interestingly the malware has advanced a lot recently and contains a number of tricks to bypass AV and avoid analysis including erasing itself if it is run in a virtual machine.

With enterprise AV unable to detect these threats what can be done to protect the endpoints and the patients? Let’s take some medical advice:

  • Isolate potential contagions – Vulnerable groups are usually the first to fall ill so focus on the browser, plugins and document viewers first. Web content such as websites, documents and plugins should be kept in isolation where possible. If we can contain a threat it cannot spread.
  • Screen and test – We can verify that some applications are known to be in the clear and not infected so we can allow list them. Start with your employees first by allow listing your standard corporate build and this will make the process much easier. Any new applications that appear can then be easily blocked until they are tested and given the all clear.
  • Give the right medicine in the right dose – Make sure that users have the appropriate privileges, don’t prescribe the same admin rights for everyone. Giving admin rights to a user facing malware threats is like giving steroids to treat an infection, you lower the systems defences and the infection takes over. Qbot relies on admin rights to disable security features and embed itself.

With these proactive defence strategies you can secure endpoints against even advanced zero day attacks without relying on detection. So be proactive today and keep the malware away.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • How BeyondTrust PAM + McAfee ePO Closes Security Gaps Across Users, Accounts, & Systems
    Oct 3, 2019 How BeyondTrust PAM + McAfee ePO Closes Security Gaps Across Users, Accounts, & Systems
    Blog
    1m
  • Elasticsearch is Here - Privilege Management for Unix & Linux and Active Directory Bridge 22.1
    Jan 31, 2022 Elasticsearch is Here - Privilege Management for Unix & Linux and Active Directory Bridge 22.1
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.