logo

Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor’s EDR Solutions

ID: c2a78d4c-a55f-58b5-b95d-e48232c25cbc

STIX ID: report--c2a78d4c-a55f-58b5-b95d-e48232c25cbc

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Qilin ransomware operators are using DLL sideloading (malicious msimg32.dll) to run a multi-stage, in-memory loader that neutralizes endpoint detection and response (EDR) products by disabling over 300 EDR drivers and loading signed kernel helper drivers (rwdrv.sys, hlpdrv.sys) to manipulate physical memory and unregister kernel callbacks; the report details advanced anti-detection techniques (SEH/VEH obfuscation, ETW suppression, syscall stubbing, kernel object tampering), notes active campaign activity and victimology, and advises monitoring for DLL sideloading, unexpected drivers, and user-mode attempts to write physical memory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.