logo

Looking Through a Pinhole at a Qilin Ransomware Attack

ID: 162785f0-0b45-56db-acf3-9c468a8a25c2

STIX ID: report--162785f0-0b45-56db-acf3-9c468a8a25c2

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-10-22

Date Updated: 2026-04-28

...
...

Huntress investigated a Qilin ransomware incident where a rogue ScreenConnect RMM was installed and used to transfer r.ps1, s.exe (likely an infostealer) and ss.exe; the actor disabled Microsoft Defender and ransom notes were created, with analysts piecing together activity from managed AV alerts, Windows Event Logs, PCA and AmCache artifacts and publishing IoCs (file hashes and a ScreenConnect instance ID) to guide response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.