logo

Qilin EDR killer infection chain

ID: 07744142-63e8-55b3-9abe-0c3a45f06b24

STIX ID: report--07744142-63e8-55b3-9abe-0c3a45f06b24

Feed Name: Cisco Talos

Threat Score
85/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

Author: Takahiro Takeda

...
...

This report analyzes a malicious msimg32.dll loader observed in Qilin ransomware attacks that implements a multi-stage in-memory PE loader and deploys an EDR-killer capable of disabling over 300 EDR drivers; it details SEH/VEH-based control-flow obfuscation, syscall bypass techniques, use of abused signed drivers for physical memory access, helper drivers to terminate protected processes, and provides hashes and IOCs for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.