logo

Microsoft links Scattered Spider hackers to Qilin ransomware attacks

ID: d7b379b4-d05f-58c2-8b39-3e1034e59a02

STIX ID: report--d7b379b4-d05f-58c2-8b39-3e1034e59a02

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-07-16

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

### Executive summary Microsoft reports that the financially motivated group Scattered Spider (Octo Tempest/0ktapus) has begun deploying Qilin ransomware in its campaigns; the group uses social-engineering TTPs (IT impersonation, phishing, MFA bombing, SIM swapping) to obtain admin access, exfiltrate data for double-extortion, and deploy an advanced Linux/VMware ESXi encryptor. Qilin has claimed over 130 victims and been linked to disruptive incidents affecting organizations including NHS hospitals and Synnovis, with ransom demands ranging from tens of thousands to millions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.