logo

New Qilin ransomware encryptor features stronger encryption, evasion

ID: e1a175a5-6536-5fb9-84d3-87a930d405d5

STIX ID: report--e1a175a5-6536-5fb9-84d3-87a930d405d5

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-10-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Qilin.B is a Rust-based evolution of the Qilin (Agenda) ransomware that adds AES-256-CTR with AES‑NI acceleration (with ChaCha20 fallback), RSA‑4096/OAEP key protection, registry persistence, termination of backup and security processes (e.g., Veeam, VSS, Sophos, Acronis), shadow copy deletion, and registry changes to share network drives; Halcyon published IOCs and the family has been tied to prior impactful attacks and an info-stealer component.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.