logo

Qilin ransomware’s newest tactics: Widespread encryption by any means necessary

ID: 56bb4336-d22e-53d9-99a6-11552f3e5003

STIX ID: report--56bb4336-d22e-53d9-99a6-11552f3e5003

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-11-21

Date Updated: 2026-05-01

...
...

This ThreatLocker report provides a technical analysis of Qilin, a Russia-based ransomware-as-a-service group responsible for hundreds of attacks; it details a Rust-based encryptor's behavior (privilege checks, password validation bypass, AES/ChaCha20 encryption), propagation mechanisms (embedded PsExec, Windows networking APIs, vCenter/ESXi targeting), destructive post-encryption actions (shadow copy deletion, event log clearing, wallpaper/ransom note deployment), and example commands/IoCs to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.