logo

Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server

ID: c14b88a2-49b1-5770-8c02-fb363290cdc1

STIX ID: report--c14b88a2-49b1-5770-8c02-fb363290cdc1

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Tushar Subhra Dutta

...
...

Qilin (Agenda) is a prolific RaaS group that has escalated since 2022 and—according to the report—surpassed 700 confirmed attacks in a year, targeting sectors including healthcare, manufacturing, finance, and government. Operators gain access via spearphishing, exploitation of vulnerabilities, and abuse of RMM tools, then use living-off-the-land techniques such as a PowerShell query of Event ID 1149 (RemoteConnectionManager Operational log) delivered via a rogue ScreenConnect to quietly map RDP activity and prioritize targets for lateral movement and double extortion; defenders are advised to enable PowerShell ScriptBlock logging, monitor RemoteConnectionManager logs, detect unauthorized remote access tools, and watch for Defender tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.