Qilin ransomware’s newest tactics: Widespread encryption by any means necessary
ID: 56bb4336-d22e-53d9-99a6-11552f3e5003
STIX ID: report--56bb4336-d22e-53d9-99a6-11552f3e5003
Feed Name: ThreatLocker Blog
This ThreatLocker report provides a technical analysis of Qilin, a Russia-based ransomware-as-a-service group responsible for hundreds of attacks; it details a Rust-based encryptor's behavior (privilege checks, password validation bypass, AES/ChaCha20 encryption), propagation mechanisms (embedded PsExec, Windows networking APIs, vCenter/ESXi targeting), destructive post-encryption actions (shadow copy deletion, event log clearing, wallpaper/ransom note deployment), and example commands/IoCs to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
