Qilin ransomware now steals credentials from Chrome browsers
ID: 38ab99f8-b5a1-5769-8916-3573c75e6013
STIX ID: report--38ab99f8-b5a1-5769-8916-3573c75e6013
Feed Name: Bleeping Computer
Sophos observed the Qilin ransomware group gain access via compromised VPN credentials, remain dormant while mapping the network, then modify Group Policy Objects to run a PowerShell script (IPScanner.ps1) and batch scripts (logon.bat/run.bat) to harvest Chrome-stored credentials from all domain-logged-in machines, exfiltrate them to a C2, wipe local traces, and ultimately deploy ransomware across the domain; recommended mitigations include enforcing MFA, prohibiting browser-stored secrets, applying least-privilege, and segmenting networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
