Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server
ID: c14b88a2-49b1-5770-8c02-fb363290cdc1
STIX ID: report--c14b88a2-49b1-5770-8c02-fb363290cdc1
Feed Name: cybersecurityNews.com
Qilin (Agenda) is a prolific RaaS group that has escalated since 2022 and—according to the report—surpassed 700 confirmed attacks in a year, targeting sectors including healthcare, manufacturing, finance, and government. Operators gain access via spearphishing, exploitation of vulnerabilities, and abuse of RMM tools, then use living-off-the-land techniques such as a PowerShell query of Event ID 1149 (RemoteConnectionManager Operational log) delivered via a rogue ScreenConnect to quietly map RDP activity and prioritize targets for lateral movement and double extortion; defenders are advised to enable PowerShell ScriptBlock logging, monitor RemoteConnectionManager logs, detect unauthorized remote access tools, and watch for Defender tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
