Targets
US, AR, AU, GB, SG
Overview
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Targeted Sectors
ConstructionBusiness ServicesManufacturingNot FoundFinancial ServicesTechnologyAgriculture and Food ProductionHealthcareConsumer ServicesEducationPublic SectorFinancialGovernmentHospitality and TourismEnergyTransportation/LogisticsTelecommunicationProfessional ServicesRetail & E-CommerceHospitalityTransportationOtherGovernment & DefenseEnergy & Utilities
Tools & Malware (25)
MimikatzEDRSandBlastPCHunterPowerToolToshiba power management driver (BYOVD)Updater for Carbon Black’s Cloud Sensor AV (upd.exe)YDArkZemana Anti-Rootkit driverNmapNpingEasyUpload.ioMEGAPowerShellPsExecWinRMfsutilProxychainsCobalt StrikeEvilginxKali Linux