Looking Through a Pinhole at a Qilin Ransomware Attack
ID: 162785f0-0b45-56db-acf3-9c468a8a25c2
STIX ID: report--162785f0-0b45-56db-acf3-9c468a8a25c2
Feed Name: Huntress Blog
Threat Score
Huntress investigated a Qilin ransomware incident where a rogue ScreenConnect RMM was installed and used to transfer r.ps1, s.exe (likely an infostealer) and ss.exe; the actor disabled Microsoft Defender and ransom notes were created, with analysts piecing together activity from managed AV alerts, Windows Event Logs, PCA and AmCache artifacts and publishing IoCs (file hashes and a ScreenConnect instance ID) to guide response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
