logo

Qilin ransomware abuses WSL to run Linux encryptors in Windows

ID: 403147ff-d54f-55be-a8b7-a7d01a08961e

STIX ID: report--403147ff-d54f-55be-a8b7-a7d01a08961e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-28

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Qilin (formerly Agenda) is a large, active ransomware operation observed deploying Linux ELF encryptors on compromised Windows hosts by enabling or using Windows Subsystem for Linux (WSL) to execute Linux payloads, while using BYOVD, signed vulnerable drivers, DLL sideloading, and remote-access tools to disable security, steal data, and encrypt VMware ESXi VMs; vendors report over 700 victims across 62 countries and ongoing high-volume activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.