216.73.217.22

Uncovering Qilin attack methods exposed through multiple cases

· Published 27/10/2025 08:11 · Modified 27/10/2025 10:34

Export JSON

Essential information

Published
27/10/2025 08:11
Modified
27/10/2025 10:34
Tags
2025-10-27 cobalt strike manufacturing qilin ransomware systembc
Related entities
17 observables, 1 intrusion sets (apt), 19 techniques (mitre), 3 malware, 13 others

Description

The group has been highly active in 2025, publishing over 40 victim cases per month on its leak site. , professional services, and wholesale trade are the most affected sectors. Attackers likely originate from Eastern Europe or Russian-speaking regions. They use tools like Cyberduck for data exfiltration and leverage notepad.exe and mspaint.exe to view sensitive information. The attack flow includes initial VPN access, reconnaissance, credential theft, lateral movement, and deployment. Two encryptors are often used: one spread via PsExec and another targeting network shares. The encrypts files, deletes backups, and leaves ransom notes. Persistence is achieved through scheduled tasks and registry modifications.

External references