logo

Qilin ransomware now steals credentials from Chrome browsers

ID: 38ab99f8-b5a1-5769-8916-3573c75e6013

STIX ID: report--38ab99f8-b5a1-5769-8916-3573c75e6013

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sophos observed the Qilin ransomware group gain access via compromised VPN credentials, remain dormant while mapping the network, then modify Group Policy Objects to run a PowerShell script (IPScanner.ps1) and batch scripts (logon.bat/run.bat) to harvest Chrome-stored credentials from all domain-logged-in machines, exfiltrate them to a C2, wipe local traces, and ultimately deploy ransomware across the domain; recommended mitigations include enforcing MFA, prohibiting browser-stored secrets, applying least-privilege, and segmenting networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.