Executive Summary
The Identity Theft Resource Center (ITRC) tracked 1,803 data compromises across all sectors in the first half of 2026, generating an estimated 471.2 million victim notices, a figure that already exceeds the 297.5 million notices issued in all of 2025 [1][2]. Healthcare compromises rose to 281, reversing a slight downward trend from the previous year and up from 270 in H1 2025 [3][4]. More than 11.7 million patients were affected across those 281 healthcare breaches as of mid-July reporting, though OCR portal data through late July showed the total climbing past 28.8 million, still below H1 2025's 42.8 million [4].
Comparitech recorded 410 ransomware attacks against healthcare sector targets in H1 2026, averaging 2.3 per day, a nearly 14% increase from the 360 attacks in H2 2025 [5]. The most active ransomware strains claiming healthcare victims were Qilin (41 claims against healthcare providers), The Gentlemen (31), LockBit (unspecified count), DragonForce (14 against healthcare businesses), The Gentlemen (13 against healthcare businesses), and INC Ransom (12 against healthcare businesses) [5]. Only 24% of H1 2026 breach notices across all sectors contained any details about the attack vector, the lowest rate the ITRC has ever recorded [2][3].
Cross-Sector Context: Mega-Breaches Distort the Aggregate Picture
The 471.2 million victim notice count is dominated by three non-healthcare incidents. A single compromise involving Instructure Holdings' Canvas education platform generated an estimated 275 million victim notices (58% of the H1 total), where the cybercrime group ShinyHunters exploited a stored cross-site scripting vulnerability in the free-tier support ticket system to obtain cross-tenant API access [1][19][22]. A breach at Under Armour produced more than 72.7 million notices, and SoundCloud contributed 29.8 million [4]. Publicly traded companies accounted for just 10.3% of compromises but generated 83.4% of all victim notices [3].
No healthcare data breaches appeared in the top 10 largest compromises for H1 2026, a contrast with H1 2025 when three healthcare breaches made the top five [4]. Supply chain attacks across all sectors generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities [3]. Zero-day attacks rose to 14 events in H1 2026, nearly matching the 17 events recorded in all of 2025 [3].
Q2 2026 alone tallied 1,029 compromises, the second-highest single-quarter total in ITRC tracking history [1][3]. The projected annual total of approximately 3,600 compromises would set a new record above 2025's 3,321 [1][2].
Healthcare-Specific Breach Data
From January 1 through April 30, 2026, HHS OCR received reports of 252 large healthcare data breaches (affecting 500 or more individuals), 8.7% fewer than the same period in 2025 (276) and 15.7% fewer than 2024 (299) [33]. The protected health information of 20.1 million individuals was exposed in that window, a 25.5% reduction from H1 2025 and a 48.8% reduction from the corresponding period in 2024 [33].
April 2026 produced 47 large breaches, 33.8% below March's 71, and well below the 12-month average of 62.4 per month [33]. Records exposed in April totaled 1,336,264 individuals, the second-lowest monthly total in the prior 12 months and an 84.9% reduction from March 2026 [33]. All four HIPAA settlements finalized in April 2026 related to ransomware attacks, and in every case OCR identified a risk analysis failure [33].
The January-through-June ITRC figure of 281 healthcare compromises captures a broader set of incidents than the OCR-reported 252 (which only covers through April 30), and the upward trend from that point through June reversed the modest downward trajectory visible in the January-April window [3][4]. Healthcare data breaches cost an average of $6.64 million in 2026 per the IBM Cost of a Data Breach Report, making healthcare the costliest sector for the thirteenth consecutive year [29].
Ransomware Against Healthcare: Volume, Targeting, and Active Groups
Of the 410 ransomware attacks Comparitech recorded against healthcare targets in H1 2026, 247 hit hospitals, clinics, and direct care providers, while 163 struck businesses within the healthcare supply chain (pharmaceutical manufacturers, medical billing providers, healthcare technology companies) [5]. Attacks on healthcare providers rose just over 3% from H2 2025. Attacks on healthcare businesses rose nearly 35%. Manufacturers within healthcare saw a 36% increase. Healthcare tech companies saw a 12% increase. Retailers (medical device retailers, drug wholesalers) saw the largest increase at 67% [5].
Among confirmed provider attacks, 55 were confirmed and 192 remained unconfirmed. The 55 confirmed attacks compromised 424,740 records with a median ransom demand of $310,000 [5].
Qilin (Agenda)
Qilin claimed 41 attacks against healthcare providers in H1 2026 [5]. The group, also tracked as Water Galura (G1050) under MITRE ATT&CK with the malware catalogued as S1242, has been active since July 2022 and operates as a Russian-speaking RaaS operation [8]. Between April 2025 and March 2026, Qilin claimed 1,358 total victims across all sectors, a 443% increase over the prior 12 months [8]. As of September 28, 2026, the group had publicly claimed 2,319 victims on its leak site [7]. No arrest, indictment, sanction, or joint government advisory has targeted Qilin as of August 2026 [8]. Affiliates gain initial access through compromised VPN credentials, phishing, and exposed remote services, then move laterally using built-in Windows administration tools before deploying encryption across Windows, Linux, and VMware ESXi environments [7]. A VPN zero-day, CVE-2026-50751, was linked to Qilin activity in June 2026 per Check Point [8]. The Qilin.B variant uses an encryption scheme designed to make recovery without the attacker's key impossible, and no public decryptor exists [8].
The Gentlemen
The Gentlemen claimed 31 attacks against healthcare providers and 13 against healthcare businesses in H1 2026 [5]. The group has claimed over 320 victims since mid-2025, with 240 attacks in 2026 alone, making it the number two most active ransomware group by victim count globally [11]. Check Point Research gained access to a live command-and-control server linked to a Gentlemen affiliate, revealing a botnet of over 1,570 likely corporate victims, a figure surpassing the group's publicly claimed numbers [11]. Manufacturing and technology are the most frequently targeted sectors, with healthcare a growing third target [11]. The group offers a 90/10 affiliate revenue split (compared to the industry-standard 80/20), which is accelerating growth by attracting experienced operators from competing programs [11].
The Gentlemen's encryptor has autonomous, worm-like lateral movement capabilities enabling rapid compromise of Active Directory and connected OT environments within hours of initial access [15]. Microsoft tracks the group as Storm-2697, with suspected administrator aliases Zeta88 and Hastalamuerte [15]. The group is believed to have been established by a disgruntled former Qilin affiliate, absorbing operators from Embargo, LockBit, Medusa, and BlackLock [15]. Initial access is often gained through exploitation of CVE-2024-55591 in FortiOS and FortiProxy devices. The group employs BYOVD attacks for defense evasion and maintains a database of compromised credentials for targeting.
In early May 2026, The Gentlemen's internal communications infrastructure was compromised and leaked publicly, exposing Rocket.Chat room exports, screenshots, and operational files spanning November 2025 through late April 2026 [39].
DragonForce
DragonForce claimed 14 attacks against healthcare businesses in H1 2026 [5]. The group has accumulated 657 total victims since its launch [18]. DragonForce restructured as a ransomware cartel in March 2025 and formed a formal coalition with LockBit and Qilin [16]. Affiliates pay 0% to 23% of ransom proceeds to the cartel operation, below the 20% standard fee [17]. DragonForce affiliates specifically seek healthcare organizations where operational disruption creates clinical risk, increasing leverage [17].
Symantec disclosed in June 2026 that DragonForce deployed a custom Go-based backdoor called Backdoor.Turn that hides C2 communications inside Microsoft Teams relay infrastructure using the TURN protocol, making traffic appear as legitimate Microsoft collaboration traffic [17]. The group entered one victim via an unpatched Microsoft SQL Server vulnerability, then spent weeks using four BYOVD techniques to terminate endpoint detection tools before deploying Backdoor.Turn [17].
Recent Healthcare Victims (Q3 2026)
The pace of healthcare-sector ransomware has continued through Q3 2026. Aesto Health disclosed on September 1, 2026, that 9,540,683 patients were affected by an intrusion into its AWS-hosted environment between December 2 and December 18, 2025, making it the second-largest confirmed U.S. healthcare breach of 2026 [28]. CareCloud confirmed a March 2026 attack on one of its EHR environments affecting over 3.7 million people, with forensic investigators placing unauthorized access within a six-day window. Astrana Health filed a materiality determination with the SEC on September 22, 2026, after a social engineering attack led to data exfiltration from its servers [26]. Two separate ransomware groups (GENESIS and Anubis) listed Interim HealthCare, a home health provider operating across roughly 40 U.S. states, on their leak sites within weeks of each other in August 2026 [24]. On September 29, 2026, the Chaos ransomware group announced a cyberattack on Carolina Asthma & Allergy Center, threatening to release 290 GB of data [25]. HIPAA Journal published a single September 3 roundup covering five separate healthcare providers in five states reporting ransomware-related breaches simultaneously, including INC Ransom claiming responsibility for the Alta Orthopaedics breach (24,496 individuals, 26 GB exfiltrated) [23].
The Transparency Problem
Only 24% of H1 2026 breach notices contained details about the attack vector, the lowest rate ever recorded by the ITRC [2][3]. In 2021, 93% of breach notices included that detail [6]. Seventy-six percent of all notices (1,378 of the total) failed to include information about the attack vector [4]. ITRC CEO Eva Velasquez said the organization sees a transparency crisis in which consumers and businesses remain largely unaware of their actual risk exposure because the state laws meant to inform and protect them do not function as intended [2]. This opacity directly impairs threat intelligence production, detection engineering prioritization, and risk modeling for any organization consuming breach notification data as an input.
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| filename | IPScanner.ps1 |
PowerShell script deployed via GPO by Qilin | [10] |
| filename | logon.bat |
Batch script deployed via GPO by Qilin | [10] |
| filename | upd.exe |
Signed executable used for DLL sideloading by Qilin | [10] |
| filename | avupdate.dll |
Malicious DLL sideloaded via upd.exe by Qilin | [10] |
| filename | main.exe |
Qilin ransomware executable | [10] |
| filename | K7RKScan.sys |
Vulnerable driver abused in DragonForce BYOVD | [17] |
| filename | ThrottleBlood.sys |
Vulnerable driver used by The Gentlemen for BYOVD | [36] |
| filename | viragt64.sys |
Vulnerable driver used by The Gentlemen to kill EDR/AV | [36] |
| filename | avastrclone.exe |
Rclone renamed for exfiltration by The Gentlemen | [36] |
| filename | secretsdump.py |
Credential extraction tool in Gentlemen/Qilin intrusions | [38] |
| filename | README-GENTLEMEN.txt |
Ransom note dropped by The Gentlemen | [39] |
| hash (SHA256) | 7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10 |
IOC associated with The Gentlemen | |
| malware | Backdoor.Turn |
Custom Go-based backdoor used by DragonForce for Teams C2 | [17] |
| malware | AdaptixC2 |
C2 framework used by The Gentlemen | [14] |
| malware | GentleKiller |
EDR killer suite distributed by The Gentlemen | [15] |
MITRE ATT&CK Techniques
The following techniques are directly supported by the source material for the ransomware groups discussed:
| ID | Name | Actor(s) | Source |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | Qilin, DragonForce, The Gentlemen | [7][17] |
| T1078 | Valid Accounts | Qilin, DragonForce, The Gentlemen | [7][10][37] |
| T1133 | External Remote Services | Qilin | [10] |
| T1566 | Phishing | Qilin, DragonForce | [10][37] |
| T1059.001 | PowerShell | Qilin | [10] |
| T1059.003 | Windows Command Shell | Qilin, The Gentlemen | [10][36] |
| T1053 | Scheduled Task/Job | Qilin | [7][10] |
| T1562.001 | Disable or Modify Security Tools | Qilin, DragonForce, The Gentlemen | [8][17] |
| T1003.001 | LSASS Memory | Qilin | [7] |
| T1021 | Remote Services | Qilin, The Gentlemen, DragonForce | [10][13][37] |
| T1021.001 | Remote Desktop Protocol | The Gentlemen | |
| T1486 | Data Encrypted for Impact | All | [5][35] |
| T1490 | Inhibit System Recovery | Qilin, The Gentlemen | [10] |
| T1047 | Windows Management Instrumentation | The Gentlemen | |
| T1570 | Lateral Tool Transfer | Qilin, The Gentlemen, DragonForce | [10][37] |
| T1041 | Exfiltration Over C2 Channel | DragonForce | [17] |
| T1569.002 | Service Execution | Qilin | [10] |
| T1068 | Exploitation for Privilege Escalation | The Gentlemen | |
| T1218 | System Binary Proxy Execution | The Gentlemen | |
| T1675 | ESXi Administration Command | Qilin | [10] |
Detection and Hunting
BYOVD Driver Loading. All three dominant groups use Bring Your Own Vulnerable Driver techniques to kill EDR/AV. Monitor for loading of known-vulnerable drivers (ThrottleBlood.sys, viragt64.sys, K7RKScan.sys, rwdrv.sys, hlpdrv.sys) outside normal baselines. Sysmon Event ID 6 (Driver Loaded) filtered against a known-good driver allowlist is the primary detection surface [7][17][36].
title: Suspicious Vulnerable Driver Load Associated with RaaS BYOVD
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
author: RedSheepSec
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\ThrottleBlood.sys'
- '\viragt64.sys'
- '\K7RKScan.sys'
- '\rwdrv.sys'
- '\hlpdrv.sys'
condition: selection
level: high
Renamed Rclone for Exfiltration. The Gentlemen rename Rclone to avastrclone.exe to blend with legitimate AV tooling [36]. Hunt for Rclone execution from non-standard paths or under unexpected filenames by correlating process creation events with known Rclone binary hashes regardless of filename.
Microsoft Teams TURN Protocol Abuse. DragonForce's Backdoor.Turn tunnels C2 over legitimate Microsoft TURN relay infrastructure [17]. Detection requires TLS inspection or behavioral analysis of QUIC sessions to Microsoft IP ranges that exhibit anomalous session duration, packet cadence, or data volume patterns inconsistent with normal Teams usage.
GPO-Deployed Scripts. Qilin deploys IPScanner.ps1 and logon.bat via Group Policy [10]. Monitor for GPO modifications (Event ID 5136 in Active Directory audit logs) creating or modifying scripts in SYSVOL, especially outside change windows.
Credential Dumping via LSASS. Abnormal lsass.exe memory access is a consistent Qilin indicator [7]. Sysmon Event ID 10 (Process Access) targeting lsass.exe with GrantedAccess values of 0x1010 or 0x1FFFFF from non-system processes should generate high-confidence alerts.
FortiOS CVE-2024-55591 Exploitation. The Gentlemen gain initial access through this vulnerability. Organizations running FortiOS or FortiProxy should verify patching status and review authentication logs for anomalous admin-level session creation from external IPs.
Analysis
Three structural observations emerge from the H1 2026 data.
First, ransomware targeting has shifted materially toward healthcare supply chain entities rather than direct care providers. The 35% increase in attacks on healthcare businesses versus the 3% increase against providers [5] indicates that threat actors are exploiting the generally weaker security posture of smaller vendors (billing companies, EHR platforms, data migration services) to achieve disproportionate downstream impact. The Aesto Health breach (9.5 million patients via a third-party archiving vendor) [28] and CareCloud breach (3.7 million patients via an EHR vendor) are direct examples.
Second, the RaaS ecosystem is consolidating and cross-pollinating. DragonForce's cartel arrangement with LockBit and Qilin [16], The Gentlemen's founding by a former Qilin affiliate who absorbed operators from Embargo, LockBit, Medusa, and BlackLock [15], and the use of overlapping tooling across groups [36] mean that tracking by group branding alone produces an incomplete picture. The TTPs converge heavily around VPN/firewall exploitation for initial access, BYOVD for defense evasion, and Rclone-based exfiltration.
Third, the 24% attack-vector disclosure rate [2][3] is actively degrading the healthcare sector's collective defense capability. Without knowing how breaches occur, defenders cannot prioritize patches, tune detections, or allocate resources based on actual threat patterns. The ITRC's own data shows this rate has been declining steadily from 93% in 2021 [6], creating a compounding intelligence gap.
Red Sheep Assessment
Confidence: Moderate
The data collectively points to a structural maturation of the healthcare ransomware problem that breach counts alone do not capture. The 8.7% decline in OCR-reported breaches through April [33] appears to conflict with the ITRC's 281-compromise figure for the full half [3] and Comparitech's 410 ransomware attacks [5]. The likely explanation is timing lag in OCR reporting combined with the difference between breach reports (OCR) and total compromises (ITRC, which includes exposures and leaks). The underlying attack tempo has not decreased.
The 67% increase in attacks against healthcare retailers and the 36% increase against manufacturers [5] suggest that ransomware operators are systematically mapping the healthcare supply chain and selecting targets based on downstream impact potential and assumed security maturity gaps. This is consistent with the broader trend of RaaS groups operating as structured intrusion operations rather than opportunistic encryption campaigns [38].
An alternative interpretation is that the rising numbers simply reflect improved tracking and reporting rather than an actual increase in attacks. The expanding coverage of ransomware monitoring platforms like Comparitech's, combined with more leak-site claims from groups seeking publicity (The Gentlemen's leak site was itself compromised in May 2026, revealing that actual victim counts exceeded public claims) [39][11], makes this partially plausible. However, the continued appearance of new, named healthcare victims week after week through September 2026 [23][24][25][26] argues against a purely methodological explanation.
The convergence of Qilin, The Gentlemen, and DragonForce around shared affiliates, tooling, and even formal cartel structures [15][16] suggests that the effective number of distinct threat actors targeting healthcare is smaller than the group-branding count implies. Defenders who build detections around specific group IOCs rather than shared TTPs will miss intrusions conducted by the same operators under different banners.
Defender's Checklist
- ▢[ ] Audit FortiOS and FortiProxy deployments for CVE-2024-55591 patch status; review authentication logs for anomalous admin session creation from external IPs. The Gentlemen use this as a primary initial access vector.
- ▢[ ] Implement driver-load allowlisting or monitor Sysmon Event ID 6 for loading of known BYOVD drivers (
ThrottleBlood.sys,viragt64.sys,K7RKScan.sys,rwdrv.sys,hlpdrv.sys). All three dominant healthcare-targeting RaaS groups use BYOVD to disable security tooling [7][17][36].
- ▢[ ] Hunt for Rclone execution under any filename by correlating process creation metadata (file hash, file description, internal name) with known Rclone binaries. Query example for Splunk:
index=edr process_internal_name="rclone" NOT process_name="rclone.exe"[36].
- ▢[ ] Review third-party vendor and business associate risk assessments with specific attention to EHR, billing, and data migration vendors. The H1 2026 data shows a 35% increase in ransomware attacks against healthcare business associates versus a 3% increase against direct providers [5].
- ▢[ ] Deploy Sysmon Event ID 10 monitoring for LSASS access from non-system processes, with alerting on
GrantedAccessvalues consistent with credential dumping (0x1010,0x1FFFFF). This is a consistent pre-encryption indicator across Qilin intrusions [7].
References
[1] https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/
[2] https://www.prnewswire.com/news-releases/itrc-malicious-insiders-surge-as-h1-2026-data-compromises-set-pace-for-record-year-302825633.html
[3] https://cybersecuritystats.com/reports/identity-theft-resource-center/itrc-h1-2026-data-breach-report
[4] https://www.hipaajournal.com/itrc-h1-2026-data-breach-report/
[5] https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
[6] https://www.upguard.com/blog/biggest-data-breaches-us
[7] https://www.provendata.com/blog/qilin-ransomware
[8] https://www.adaptivesecurity.com/blog/qilin-ransomware
[9] https://www.dexpose.io/qilin-ransomware/
[10] https://blackpointcyber.com/wp-content/uploads/2026/01/Qilin.pdf
[11] https://blog.checkpoint.com/research/the-gentlemen-a-new-ransomware-threat-climbing-the-charts-fast/
[12] https://cyfirma.com/news/weekly-intelligence-report-25-sep-2026
[13] https://securityarsenal.com/blog/thegentlemen-ransomware-gang-5-victims-in-5-days-transportation-healthcare-and-technology-under-active-fire
[14] https://www.rescana.com/post/ransomware-attacks-in-japan-h1-2026-analysis-of-the-gentlemen-raas-qilin-ai-generated-tools-and-glpi-vulnerabilities
[15] https://shieldworkz.com/blogs/threat-intelligence-briefing-the-gentlemen-ransomware
[16] https://www.dexpose.io/dragonforce-ransomware/
[17] https://www.decryptiondigest.com/blog/dragonforce-backdoor-turn-microsoft-teams-c2-ransomware
[18] https://www.ransomware.live/group/dragonforce
[19] https://scotthelme.co.uk/the-instructure-canvas-breach-2026-how-xss-in-a-support-ticket-compromised-275-million-students/
[20] https://www.penligent.ai/hackinglabs/canvas-cyber-security-incident/
[21] https://redriver.com/education/the-canvas-hack-how-shinyhunters-breached-instructure
[22] https://tech-insider.org/instructure-canvas-shinyhunters-breach-2026/
[23] https://centrexit.com/blog/five-healthcare-ransomware-breaches-what-they-share/
[24] https://tech-insider.org/interim-healthcare-ransomware-genesis-attack-2026/
[25] https://dexpose.io/chaos-ransomware-strikes-carolina-asthma-allergy-center
[26] https://shattered.io/astrana-health-data-breach-sec-filing-2026
[27] https://swktech.com/swk-cybersecurity-news-recap-september-2026
[28] https://tech-insider.org/aesto-health-data-breach-9-5-million-patients-2026/
[29] https://www.stingrai.io/blog/healthcare-data-breach-statistics-2026
[30] https://deepstrike.io/blog/healthcare-cybersecurity-statistics
[31] https://www.hipaajournal.com/healthcare-data-breach-statistics/
[32] https://www.faxsipit.com/blogs/hipaa-violation-statistics
[33] https://www.hipaajournal.com/april-2026-healthcare-data-breach-report/
[34] https://www.faxsipit.com/blogs/healthcare-data-breach-statistics
[35] https://www.resecurity.com/blog/article/dragonforce-ransomware-reverse-engineering-report
[36] https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/
[37] https://blackpointcyber.com/wp-content/uploads/2026/02/DragonForce-1.pdf
[38] https://blog.netmanageit.com/japanese-ransomware-the-gentlemen-qilin-2026/
[39] https://ransom-isac.org/blog/the-gentlemen-leak-analysis/
Event Timeline
Timeline
Entity Relationships
Entity Graph (9 entities, 7 relationships)
Diamond Model
Diamond Model
Hunt Guide: Healthcare-Targeting RaaS Groups (Qilin, The Gentlemen, DragonForce) with BYOVD, Supply Chain Exploitation, and Cartel Coordination
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Qilin, The Gentlemen, or DragonForce affiliates are active in our environment, we expect to observe BYOVD driver loading (ThrottleBlood.sys, viragt64.sys, K7RKScan.sys, rwdrv.sys, hlpdrv.sys), GPO-deployed PowerShell/batch scripts in SYSVOL, renamed Rclone binaries, LSASS credential dumping access patterns, anomalous FortiOS admin sessions from external IPs, and C2 traffic to known infrastructure IPs in Sysmon, Windows Security, CrowdStrike, PowerShell, and network telemetry sources.
Intelligence Summary: In H1 2026, Comparitech recorded 410 ransomware attacks against healthcare targets (2.3 per day), a 14% increase over H2 2025, with attacks on healthcare supply chain businesses rising 35% while direct provider attacks rose only 3%. Qilin (41 healthcare claims), The Gentlemen (44 combined), and DragonForce (14) are the most active groups, sharing affiliates, tooling, and a formal cartel structure. All three groups converge on VPN/firewall exploitation for initial access (including CVE-2024-55591 and CVE-2026-50751), BYOVD for defense evasion, LSASS credential dumping, and Rclone-based exfiltration, while DragonForce has deployed a custom Go-based backdoor (Backdoor.Turn) that tunnels C2 through Microsoft Teams TURN relay infrastructure.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All healthcare networks, EHR/clinical application servers, Active Directory domains, VPN/remote access concentrators (especially FortiOS/FortiProxy), VMware ESXi hypervisor clusters, and third-party vendor connectivity segments. Include DMZ segments hosting externally accessible services.
- Timeframe: 90-day retrospective hunt covering July 1, 2026 through October 1, 2026. Extend to 180 days for IOC sweeps against DragonForce and Qilin infrastructure given the documented dwell times (Aesto Health intrusion spanned December 2-18, 2025, disclosed September 2026).
- Priority Systems: Domain controllers, FortiOS/FortiProxy appliances, VMware ESXi hosts, EHR application servers, medical device management servers, VPN concentrators, backup infrastructure, and any systems with direct connectivity to third-party healthcare business associates (billing, EHR vendors, data migration services).
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
Qilin exploits VPN zero-days (CVE-2026-50751). The Gentlemen exploit CVE-2024-55591 in FortiOS/FortiProxy. DragonForce exploits unpatched Microsoft SQL Server instances. All three groups target internet-facing appliances as their primary entry vector.
Splunk SPL:
index=firewall-pan sourcetype="pan:threat" severity="critical" OR severity="high" action="allowed"
| eval threat_name=lower(threat_name)
| search threat_name="*fortios*" OR threat_name="*fortiproxy*" OR threat_name="*cve-2024-55591*" OR threat_name="*cve-2026-50751*" OR threat_name="*sql*injection*"
| stats count by src_ip, dest_ip, threat_name, action
| sort -count
Elastic KQL:
event.dataset:"panw.threat" AND (threat.name:*fortios* OR threat.name:*fortiproxy* OR threat.name:*CVE-2024-55591* OR threat.name:*CVE-2026-50751* OR threat.name:*sql*injection*) AND event.outcome:"allowed"
Sigma Rule:
title: FortiOS CVE-2024-55591 or VPN CVE-2026-50751 Exploitation Attempt
id: f8a2b3c4-d5e6-7890-abcd-ef1234567891
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects firewall or IDS alerts matching CVE-2024-55591 (FortiOS/FortiProxy) or CVE-2026-50751 (VPN zero-day) exploitation patterns used by The Gentlemen and Qilin.
logsource:
category: ids
product: network
detection:
selection:
signature|contains:
- 'CVE-2024-55591'
- 'CVE-2026-50751'
- 'FortiOS'
condition: selection
level: critical
tags:
- attack.initial_access
- attack.t1190
Correlate with FortiOS authentication logs for anomalous admin-level session creation from external IPs. FortiProxy and FortiOS devices running versions prior to the CVE-2024-55591 patch are the primary targets. Check for any new admin accounts created shortly after external authentication events.
T1078: Valid Accounts (Initial Access) [P2]
All three groups leverage compromised VPN credentials and stolen credentials from credential databases. The Gentlemen maintain a database of compromised credentials for targeting. Qilin affiliates gain access through compromised VPN credentials.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10
| eval hour=strftime(_time, "%H")
| where hour < "06" OR hour > "22"
| stats count dc(dest) as unique_hosts by src_ip, user
| where unique_hosts > 3
| sort -unique_hosts
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" AND (NOT source.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16))
Sigma Rule:
title: RDP Logon from External IP During Off-Hours
id: f8a2b3c4-d5e6-7890-abcd-ef1234567892
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects Type 10 (RemoteInteractive/RDP) logon events from external IPs during non-business hours, consistent with Qilin and The Gentlemen lateral movement patterns.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
filter_internal:
IpAddress|startswith:
- '10.'
- '172.16.'
- '172.17.'
- '172.18.'
- '172.19.'
- '172.20.'
- '172.21.'
- '172.22.'
- '172.23.'
- '172.24.'
- '172.25.'
- '172.26.'
- '172.27.'
- '172.28.'
- '172.29.'
- '172.30.'
- '172.31.'
- '192.168.'
condition: selection and not filter_internal
level: high
tags:
- attack.initial_access
- attack.t1078
High false positive rate in environments with legitimate remote access. Tune by excluding known VPN egress ranges and authorized remote support IPs. Correlate with VPN authentication failures preceding success for credential stuffing patterns.
T1059.001: PowerShell (Execution) [P1]
Qilin deploys IPScanner.ps1 via GPO to enumerate the network. PowerShell is used for reconnaissance and payload staging across Qilin intrusions.
Splunk SPL:
index=powershell sourcetype="XmlWinEventLog" EventCode=4104
| search ScriptBlockText="*IPScanner*" OR ScriptBlockText="*Test-Connection*" OR ScriptBlockText="*Net.Sockets*" OR ScriptBlockText="*invoke-portscan*" OR ScriptBlockText="*nslookup*" OR ScriptBlockText="*Resolve-DnsName*"
| stats count by Computer, ScriptBlockText
| sort -count
Elastic KQL:
event.code:"4104" AND powershell.file.script_block_text:(*IPScanner* OR *Test-Connection* OR *Net.Sockets* OR *invoke-portscan*)
Sigma Rule:
title: Qilin GPO-Deployed IPScanner PowerShell Script
id: f8a2b3c4-d5e6-7890-abcd-ef1234567893
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects execution of IPScanner.ps1, a PowerShell reconnaissance script deployed via GPO by Qilin ransomware affiliates.
logsource:
product: windows
category: process_creation
detection:
selection_filename:
CommandLine|contains: 'IPScanner'
selection_scriptpath:
CommandLine|contains:
- '\SYSVOL\'
- '\Policies\'
condition: selection_filename or selection_scriptpath
level: high
tags:
- attack.execution
- attack.t1059.001
- attack.discovery
- attack.t1046
IPScanner.ps1 is specifically documented in Qilin GPO deployments. Also hunt for any .ps1 files deployed through SYSVOL that do not match organizational baselines. ScriptBlock logging (EventCode 4104) provides the script content; Module logging (4103) provides invocation details.
T1562.001: Disable or Modify Security Tools (Defense Evasion) [P1]
All three groups use BYOVD techniques to terminate EDR and AV processes. Vulnerable drivers include ThrottleBlood.sys, viragt64.sys, K7RKScan.sys, rwdrv.sys, and hlpdrv.sys. The Gentlemen distribute a dedicated EDR killer suite called GentleKiller. DragonForce used four distinct BYOVD techniques in a single intrusion before deploying Backdoor.Turn.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=6
| eval driver_name=lower(ImageLoaded)
| search driver_name="*throttleblood.sys" OR driver_name="*viragt64.sys" OR driver_name="*k7rkscan.sys" OR driver_name="*rwdrv.sys" OR driver_name="*hlpdrv.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
| sort -count
Elastic KQL:
event.code:"6" AND (file.path:(*ThrottleBlood.sys OR *viragt64.sys OR *K7RKScan.sys OR *rwdrv.sys OR *hlpdrv.sys))
Sigma Rule:
title: Suspicious Vulnerable Driver Load Associated with RaaS BYOVD
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects loading of known vulnerable drivers used by Qilin, The Gentlemen, and DragonForce for BYOVD attacks to disable EDR and AV tools.
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\ThrottleBlood.sys'
- '\viragt64.sys'
- '\K7RKScan.sys'
- '\rwdrv.sys'
- '\hlpdrv.sys'
condition: selection
level: high
tags:
- attack.defense_evasion
- attack.t1562.001
The LOLDrivers project maintains a comprehensive list of vulnerable drivers; consider extending this detection with their full catalog. False positives may occur if these drivers are legitimately installed (K7 Computing antivirus uses K7RKScan.sys). Validate against your software inventory. Also monitor for new service installations (EventID 7045) for these driver names.
T1003.001: LSASS Memory (Credential Access) [P1]
Qilin consistently targets lsass.exe memory for credential extraction. secretsdump.py is also used in Qilin and Gentlemen intrusions for credential harvesting from domain controllers.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=10 TargetImage="*\lsass.exe"
| eval access_hex=GrantedAccess
| where access_hex="0x1010" OR access_hex="0x1FFFFF" OR access_hex="0x1410" OR access_hex="0x143a"
| search NOT SourceImage="*\csrss.exe" NOT SourceImage="*\wininit.exe" NOT SourceImage="*\wmiprvse.exe" NOT SourceImage="*\svchost.exe" NOT SourceImage="*\MsMpEng.exe"
| stats count by Computer, SourceImage, GrantedAccess
| sort -count
Elastic KQL:
event.code:"10" AND winlog.event_data.TargetImage:*lsass.exe AND (winlog.event_data.GrantedAccess:("0x1010" OR "0x1FFFFF" OR "0x1410" OR "0x143a")) AND NOT winlog.event_data.SourceImage:(*csrss.exe OR *wininit.exe OR *wmiprvse.exe OR *svchost.exe OR *MsMpEng.exe)
Sigma Rule:
title: LSASS Memory Access Consistent with Credential Dumping
id: f8a2b3c4-d5e6-7890-abcd-ef1234567894
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects non-system processes accessing lsass.exe memory with GrantedAccess values consistent with credential dumping, a consistent pre-encryption indicator in Qilin ransomware intrusions.
logsource:
category: process_access
product: windows
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess:
- '0x1010'
- '0x1FFFFF'
- '0x1410'
- '0x143a'
filter_system:
SourceImage|endswith:
- '\csrss.exe'
- '\wininit.exe'
- '\wmiprvse.exe'
- '\svchost.exe'
- '\MsMpEng.exe'
- '\lsass.exe'
condition: selection and not filter_system
level: high
tags:
- attack.credential_access
- attack.t1003.001
This is a high-fidelity detection when properly baselined. Whitelist your EDR agent, SIEM agent, and any legitimately installed security products that access LSASS. The 0x1FFFFF access mask indicates PROCESS_ALL_ACCESS, nearly always malicious from non-system processes.
T1059.003: Windows Command Shell (Execution) [P2]
Qilin deploys logon.bat via GPO for persistence and execution. The Gentlemen use cmd.exe for various post-exploitation activities.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\cmd.exe"
| search CommandLine="*logon.bat*" OR CommandLine="*SYSVOL*" OR CommandLine="*GPO*" OR (ParentImage="*\svchost.exe" CommandLine="*\\*\NETLOGON\*")
| stats count by Computer, ParentImage, CommandLine
| sort -count
Elastic KQL:
event.code:"1" AND process.executable:*cmd.exe AND (process.command_line:(*logon.bat* OR *SYSVOL* OR *NETLOGON*))
Sigma Rule:
title: GPO Deployed Batch Script Execution via logon.bat
id: f8a2b3c4-d5e6-7890-abcd-ef1234567895
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects execution of logon.bat scripts deployed through Group Policy, consistent with Qilin ransomware TTPs.
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'logon.bat'
ParentImage|endswith:
- '\svchost.exe'
condition: selection
level: medium
tags:
- attack.execution
- attack.t1059.003
- attack.persistence
- attack.t1547
Legitimate logon scripts exist in many environments. Baseline your GPO-deployed scripts and alert on any new additions. Cross-reference with AD audit Event ID 5136 for GPO object modifications.
T1486: Data Encrypted for Impact (Impact) [P1]
All three groups deploy ransomware encryption across Windows, Linux, and VMware ESXi environments. Qilin.B uses an encryption scheme designed to prevent recovery without the attacker key. The Gentlemen encryptor has autonomous worm-like lateral movement. Median ransom demand for confirmed healthcare provider attacks was $310,000.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=11
| eval filename=lower(TargetFilename)
| search filename="*readme-gentlemen*" OR filename="*.qilin" OR filename="*.dragonforce" OR filename="*readme*ransom*" OR filename="*decrypt*"
| stats count by Computer, TargetFilename, Image
| sort -count
Elastic KQL:
event.code:"11" AND (file.path:(*README-GENTLEMEN* OR *.qilin OR *.dragonforce OR *readme*ransom* OR *decrypt*))
Sigma Rule:
title: Ransomware Note File Creation by Healthcare-Targeting RaaS Groups
id: f8a2b3c4-d5e6-7890-abcd-ef1234567896
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects creation of ransom note files associated with Qilin, The Gentlemen, or DragonForce ransomware groups.
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|contains:
- 'README-GENTLEMEN'
- 'RECOVER-'
- '-DECRYPT'
condition: selection
level: critical
tags:
- attack.impact
- attack.t1486
By the time ransom notes appear, encryption is underway. This detection is primarily useful for confirming an active incident and triggering immediate containment. Pair with volume shadow copy deletion and backup service termination detections for earlier warning.
T1490: Inhibit System Recovery (Impact) [P1]
Qilin and The Gentlemen delete volume shadow copies and disable recovery options before encryption. Qilin uses wbadmin.exe for backup deletion.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1
| search (Image="*\vssadmin.exe" CommandLine="*delete shadows*") OR (Image="*\wmic.exe" CommandLine="*shadowcopy*delete*") OR (Image="*\wbadmin.exe" CommandLine="*delete*") OR (Image="*\bcdedit.exe" CommandLine="*recoveryenabled*no*")
| stats count by Computer, Image, CommandLine, User
| sort -count
Elastic KQL:
(process.executable:*vssadmin.exe AND process.command_line:*delete*shadows*) OR (process.executable:*wmic.exe AND process.command_line:*shadowcopy*delete*) OR (process.executable:*wbadmin.exe AND process.command_line:*delete*) OR (process.executable:*bcdedit.exe AND process.command_line:*recoveryenabled*no*)
Sigma Rule:
title: Shadow Copy and Backup Deletion Pre-Encryption Activity
id: f8a2b3c4-d5e6-7890-abcd-ef1234567897
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects deletion of shadow copies, backup catalogs, and recovery settings consistent with pre-encryption preparation by Qilin, The Gentlemen, and other ransomware groups.
logsource:
category: process_creation
product: windows
detection:
sel_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains|all:
- 'delete'
- 'shadows'
sel_wbadmin:
Image|endswith: '\wbadmin.exe'
CommandLine|contains: 'delete'
sel_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'recoveryenabled'
- 'no'
condition: sel_vssadmin or sel_wbadmin or sel_bcdedit
level: critical
tags:
- attack.impact
- attack.t1490
Very low false positive rate. Legitimate backup rotation rarely uses vssadmin delete shadows /all. Any occurrence outside scheduled backup windows warrants immediate investigation.
T1041: Exfiltration Over C2 Channel (Exfiltration) [P1]
DragonForce deploys Backdoor.Turn, a custom Go-based backdoor that tunnels C2 communications inside Microsoft Teams TURN relay infrastructure, making traffic appear as legitimate Microsoft collaboration traffic. The Gentlemen rename Rclone to avastrclone.exe for data exfiltration.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1
| eval proc_lower=lower(Image)
| search proc_lower="*avastrclone*" OR proc_lower="*rclone*"
| search NOT Image="*\Program Files*\rclone\rclone.exe"
| stats count by Computer, Image, CommandLine, ParentImage
| sort -count
Elastic KQL:
(process.executable:*avastrclone* OR (process.executable:*rclone* AND NOT process.executable:*Program?Files*rclone*rclone.exe))
Sigma Rule:
title: Renamed Rclone Execution for Data Exfiltration
id: f8a2b3c4-d5e6-7890-abcd-ef1234567898
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects execution of Rclone under non-standard filenames, specifically avastrclone.exe as used by The Gentlemen ransomware group for data exfiltration.
logsource:
category: process_creation
product: windows
detection:
selection_renamed:
Image|endswith: '\avastrclone.exe'
selection_description:
Product: 'Rclone'
filter_legit:
Image|endswith: '\rclone.exe'
condition: selection_renamed or (selection_description and not filter_legit)
level: high
tags:
- attack.exfiltration
- attack.t1041
- attack.t1567
Rclone is rarely if ever authorized in healthcare/DoD environments. Any Rclone execution should be investigated regardless of filename. Use file hash correlation to detect renamed copies. The internal product name field in the PE header will still read 'Rclone' even when renamed.
T1570: Lateral Tool Transfer (Lateral Movement) [P2]
All three groups transfer tools laterally using SMB, PsExec, and other built-in Windows utilities. The Gentlemen encryptor has autonomous worm-like lateral movement capabilities that can rapidly compromise Active Directory environments.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\psexec*"
| stats count dc(Computer) as unique_hosts by User, CommandLine
| where unique_hosts > 3
| sort -unique_hosts
Elastic KQL:
event.code:"1" AND process.executable:*psexec* | stats count by user.name, process.command_line
Sigma Rule:
title: PsExec Lateral Movement to Multiple Hosts
id: f8a2b3c4-d5e6-7890-abcd-ef1234567899
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects PsExec execution patterns consistent with ransomware lateral movement across multiple endpoints.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\psexec.exe'
- '\psexec64.exe'
CommandLine|contains: '\\'
condition: selection
level: high
tags:
- attack.lateral_movement
- attack.t1570
- attack.t1021.002
PsExec is used by system administrators. Baseline authorized use and correlate with service installation events (EventID 7045 with PSEXESVC). Unauthorized PsExec in conjunction with other TTPs from this report is high-confidence malicious.
T1133: External Remote Services (Initial Access) [P2]
Qilin affiliates gain initial access through compromised VPN credentials and exposed remote services. CVE-2026-50751, a VPN zero-day, was linked to Qilin activity in June 2026.
Splunk SPL:
index=firewall-pan sourcetype="pan:traffic:aggregated" dest_port=443 OR dest_port=8443 OR dest_port=10443 app="ssl" OR app="ipsec-esp-udp" OR app="ssl-vpn"
| stats count dc(src_ip) as unique_sources by dest_ip, dest_port, app
| where count > 50 AND unique_sources > 10
| sort -count
Elastic KQL:
destination.port:(443 OR 8443 OR 10443) AND network.application:(ssl-vpn OR ipsec OR "global-protect")
Focus on authentication anomalies: successful VPN logins from new geolocations, logins at unusual hours, or rapid sequential logins from different source IPs for the same account.
T1675: ESXi Administration Command (Execution) [P2]
Qilin deploys encryption across VMware ESXi environments. The Qilin.B variant targets ESXi hypervisors, encrypting virtual machine disk files and rendering entire virtualization stacks inoperable.
Splunk SPL:
index=linux-server sourcetype="vmware:esxlog:hostd" OR sourcetype="vmware:esxlog:vmkernel"
| search "esxcli" OR "vim-cmd" OR "esxcfg" OR "vmkfstools"
| eval suspicious=if(match(_raw, "(?i)(encrypt|destroy|delete|poweroff)"), "yes", "no")
| where suspicious="yes"
| stats count by host, _raw
| sort -count
Elastic KQL:
host.os.family:"linux" AND process.command_line:(esxcli OR vim-cmd OR vmkfstools) AND process.command_line:(encrypt* OR destroy OR delete OR poweroff)
Requires ESXi shell/SSH logging to be enabled and forwarded. Many environments lack this telemetry. Verify that ESXi host logs are being collected. Any unauthorized esxcli or vim-cmd activity warrants immediate investigation.
T1566: Phishing (Initial Access) [P2]
Qilin and DragonForce use phishing as an initial access vector. Astrana Health's September 2026 breach began with a social engineering attack that led to data exfiltration.
Splunk SPL:
index=crowdstrike sourcetype="crowdstrike:falcon:detections:json"
| search (tactic="Initial Access" AND technique="Phishing") OR (tactic="Execution" AND parent_process_name="outlook.exe")
| stats count by hostname, filename, commandline, tactic, technique
| sort -count
Elastic KQL:
event.dataset:"crowdstrike.falcon_detections" AND (threat.technique.name:Phishing OR process.parent.executable:*outlook.exe)
Monitor for Office applications spawning PowerShell, cmd, mshta, wscript, or cscript. These child-process patterns are consistent with phishing document execution chains used by Qilin and DragonForce affiliates.
T1047: Windows Management Instrumentation (Execution) [P2]
The Gentlemen use WMI for remote execution and lateral movement. Registry modifications to WMI Autologger paths (HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\ReadyBoot) are used to disable logging.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=13
| search TargetObject="*CurrentControlSet\\Control\\WMI\\Autologger*"
| stats count by Computer, TargetObject, Details, Image
| sort -count
Elastic KQL:
event.code:"13" AND registry.path:*CurrentControlSet*Control*WMI*Autologger*
Sigma Rule:
title: WMI Autologger Registry Modification for Logging Evasion
id: f8a2b3c4-d5e6-7890-abcd-ef1234567900
status: experimental
author: RedSheepSec
date: 2026/10/02
description: Detects registry modifications to WMI Autologger keys used by The Gentlemen ransomware group to disable Windows logging mechanisms.
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains|all:
- 'Control\WMI\Autologger'
Details|contains:
- '0'
condition: selection
level: high
tags:
- attack.execution
- attack.t1047
- attack.defense_evasion
- attack.t1562.001
Disabling WMI Autologger is a defense evasion technique that reduces forensic evidence. Any modification to these registry keys outside of documented maintenance should be investigated.
T1569.002: Service Execution (Execution) [P2]
Qilin creates Windows services for persistence and execution of ransomware payloads. Service installation combined with the use of upd.exe for DLL sideloading (avupdate.dll) is a documented Qilin TTP.
Splunk SPL:
index=winevent sourcetype="WinEventLog" EventCode=7045
| search Service_File_Name="*upd.exe*" OR Service_File_Name="*main.exe*" OR Service_File_Name="*avupdate*" OR Service_File_Name="*\\SYSVOL\\*"
| stats count by Computer, Service_Name, Service_File_Name, Service_Start_Type
| sort -count
Elastic KQL:
event.code:"7045" AND (winlog.event_data.ImagePath:(*upd.exe* OR *main.exe* OR *avupdate* OR *SYSVOL*))
Service installations from temp directories, user profile paths, or SYSVOL are suspicious. Correlate with Sysmon EventID 1 process creation to identify the parent process that initiated the service installation.
Indicators of Compromise
| Type | Value | Context | |
|---|---|---|---|
| ip | 31.41.244.100 |
Qilin ransomware known IP address (RU) \ | AbuseIPDB confidence 0% (0 reports, RU) |
| ip | 192.36.27.51 |
DragonForce backdoor tool download IP (DK) \ | AbuseIPDB confidence 0% (0 reports, DK) |
| ip | 45.135.232.195 |
IP listed on DragonForce group page (RU) \ | AbuseIPDB confidence 0% (0 reports, RU) |
| ip | 2.147.68.96 |
DragonForce ransomware C2 IP (IR) \ | AbuseIPDB confidence 0% (0 reports, IR) |
| ip | 185.59.221.75 |
DragonForce ransomware C2 IP (GB), AbuseIPDB confidence 19% \ | AbuseIPDB confidence 19% (5 reports, GB) |
| ip | 69.4.234.20 |
DragonForce ransomware C2 IP (US) \ | AbuseIPDB confidence 0% (0 reports, US) |
| hash_sha256 | b9bba02d18bacc4bc8d9e4f70657d381568075590cc9d0e7590327d854224b32 |
DragonForce ransomware file hash (VT 64/75 malicious) \ | VirusTotal 64/75 malicious (ransomware.dragonforce/conti) |
| hash_sha256 | ba1be94550898eedb10eb73cb5383a2d1050e96ec4df8e0bf680d3e76a9e2429 |
DragonForce ransomware file hash (VT 64/75 malicious) \ | VirusTotal 64/75 malicious (ransomware.dragonforce/conti) |
| hash_sha256 | d626eb0565fac677fdc13fb0555967dc31e600c74fbbd110b744f8e3a59dd3f9 |
DragonForce ransomware file hash (VT 64/75 malicious) \ | VirusTotal 64/75 malicious (ransomware.conti/glow) |
| hash_sha256 | 1250ba6f25fd60077f698a2617c15f89d58c1867339bfd9ee8ab19ce9943304b |
DragonForce ransomware file hash (VT 53/75 malicious) \ | VirusTotal 53/75 malicious (ransomware.lockbit/blackmatter) |
| hash_sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 |
DragonForce ransomware file hash (VT 64/75 malicious) \ | VirusTotal 64/75 malicious (miner.bitmin/nsis) |
| hash_sha256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 |
DragonForce ransomware file hash (VT 58/75 malicious) \ | VirusTotal 58/75 malicious (trojan.nsis/aavt) |
| hash_sha256 | 07ab218d5c865cb4fe78353340ab923e24a1f2881ec7206520651c5246b1a492 |
DragonForce ransomware file hash (VT 14/75 malicious) \ | VirusTotal 14/75 malicious (trojan.note/rawld) |
| hash_sha256 | 330730d65548d621d46ed9db939c434bc54cada516472ebef0a00422a5ed5819 |
DragonForce ransomware file hash (VT 53/75 malicious) \ | VirusTotal 53/75 malicious (trojan.msil/marsilia) |
| hash_sha256 | 9479a5dc61284ccc3f063ebb38da9f63400d8b25d8bca8d04b1832f02fac24de |
DragonForce ransomware file hash (VT 59/75 malicious) \ | VirusTotal 59/75 malicious (ransomware.babuk/dump) |
| hash_sha256 | 51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2 |
The Gentlemen RaaS ransomware sample (VT 51/75 malicious) \ | VirusTotal 51/75 malicious (trojan.razr/casdet) |
| hash_sha256 | 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 |
The Gentlemen RaaS Windows ransomware sample (VT 49/75 malicious) \ | VirusTotal 49/75 malicious (ransomware.gentlemen/gentleman) |
| hash_md5 | 12e22f588f6128cf1a042d1122556cd2 |
DragonForce ransomware IOC hash (VT 51/74 malicious) \ | VirusTotal 51/74 malicious (ransomware.conti/dragonforce) |
| hash_md5 | 15634dc79981e7fba25fb8530cedb981 |
DragonForce ransomware IOC hash (VT 63/75 malicious) \ | VirusTotal 63/75 malicious (ransomware.conti/glow) |
| filename | IPScanner.ps1 |
PowerShell reconnaissance script deployed via GPO by Qilin | |
| filename | logon.bat |
Batch script deployed via GPO by Qilin for persistence and execution | |
| filename | upd.exe |
Signed executable used for DLL sideloading by Qilin | |
| filename | avupdate.dll |
Malicious DLL sideloaded via upd.exe by Qilin | |
| filename | main.exe |
Qilin ransomware executable | |
| filename | K7RKScan.sys |
Vulnerable driver abused in DragonForce BYOVD attacks | |
| filename | ThrottleBlood.sys |
Vulnerable driver used by The Gentlemen for BYOVD EDR/AV killing | |
| filename | viragt64.sys |
Vulnerable driver used by The Gentlemen to kill EDR/AV | |
| filename | rwdrv.sys |
BYOVD driver used by Qilin ransomware | |
| filename | hlpdrv.sys |
Driver that kills security tools in Qilin attack | |
| filename | avastrclone.exe |
Rclone renamed for data exfiltration by The Gentlemen | |
| filename | secretsdump.py |
Credential extraction tool used in Gentlemen/Qilin intrusions | |
| filename | README-GENTLEMEN.txt |
Ransom note dropped by The Gentlemen ransomware group | |
| filename | msimg32.dll |
Multi-stage loader used in Qilin ransomware attack | |
| filename | psexec.exe |
Lateral movement tool used by The Gentlemen ransomware gang | |
| filename | rclone.exe |
Exfiltration tool used by The Gentlemen ransomware gang | |
| filename | wbadmin.exe |
Backup deletion utility abused by Qilin for recovery inhibition | |
| filename | rdpclip.exe |
Tool used to facilitate clipboard access in Qilin intrusion | |
| filename | iexplore.exe |
Used to view sensitive data in Qilin attack (uncommon in modern environments) | |
| registry | HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\ReadyBoot |
The Gentlemen disabling logging via WMI Autologger registry key modification | |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Endpoint |
The Gentlemen removing Bitdefender via registry key manipulation | |
| registry | HKLM\SYSTEM\ControlSet001\Services\msiserver |
Regpwn tool used by The Gentlemen ransomware group | |
| domain | z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion |
DragonForce ransomware data leak site \ | VirusTotal 11/91 malicious |
| domain | 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion |
DragonForce ransomware data leak site \ | VirusTotal 6/91 malicious |
IOC Sweep Queries (Splunk):
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="31.41.244.100" OR dest_ip="31.41.244.100")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="192.36.27.51" OR dest_ip="192.36.27.51")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="45.135.232.195" OR dest_ip="45.135.232.195")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="2.147.68.96" OR dest_ip="2.147.68.96")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="185.59.221.75" OR dest_ip="185.59.221.75")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=firewall-pan sourcetype="pan:traffic:aggregated" (src_ip="69.4.234.20" OR dest_ip="69.4.234.20")
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, action
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
index=sysmon sourcetype="XmlWinEventLog" Hashes="*b9bba02d18bacc4bc8d9e4f70657d381568075590cc9d0e7590327d854224b32*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*ba1be94550898eedb10eb73cb5383a2d1050e96ec4df8e0bf680d3e76a9e2429*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*d626eb0565fac677fdc13fb0555967dc31e600c74fbbd110b744f8e3a59dd3f9*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*1250ba6f25fd60077f698a2617c15f89d58c1867339bfd9ee8ab19ce9943304b*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*07ab218d5c865cb4fe78353340ab923e24a1f2881ec7206520651c5246b1a492*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*330730d65548d621d46ed9db939c434bc54cada516472ebef0a00422a5ed5819*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*9479a5dc61284ccc3f063ebb38da9f63400d8b25d8bca8d04b1832f02fac24de*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*12e22f588f6128cf1a042d1122556cd2*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" Hashes="*15634dc79981e7fba25fb8530cedb981*"
| stats count by Computer, Image, Hashes
index=sysmon sourcetype="XmlWinEventLog" (EventCode=1 OR EventCode=11) (CommandLine="*IPScanner.ps1*" OR TargetFilename="*IPScanner.ps1*")
| stats count by Computer, Image, CommandLine, TargetFilename
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 CommandLine="*logon.bat*"
| search NOT CommandLine="*legitimate_known_path*"
| stats count by Computer, ParentImage, CommandLine
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\upd.exe"
| stats count by Computer, Image, CommandLine, ParentImage, Hashes
index=sysmon sourcetype="XmlWinEventLog" EventCode=7 ImageLoaded="*\avupdate.dll"
| stats count by Computer, Image, ImageLoaded, Hashes
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\main.exe"
| search NOT Image="*\Program Files*"
| stats count by Computer, Image, CommandLine, ParentImage, Hashes
index=sysmon sourcetype="XmlWinEventLog" EventCode=6 ImageLoaded="*\K7RKScan.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
index=sysmon sourcetype="XmlWinEventLog" EventCode=6 ImageLoaded="*\ThrottleBlood.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
index=sysmon sourcetype="XmlWinEventLog" EventCode=6 ImageLoaded="*\viragt64.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
index=sysmon sourcetype="XmlWinEventLog" EventCode=6 ImageLoaded="*\rwdrv.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
index=sysmon sourcetype="XmlWinEventLog" EventCode=6 ImageLoaded="*\hlpdrv.sys"
| stats count by Computer, ImageLoaded, Hashes, Signed, Signature
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\avastrclone.exe"
| stats count by Computer, Image, CommandLine, ParentImage, Hashes
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 CommandLine="*secretsdump*"
| stats count by Computer, Image, CommandLine, ParentImage
index=sysmon sourcetype="XmlWinEventLog" EventCode=11 TargetFilename="*README-GENTLEMEN*"
| stats count by Computer, Image, TargetFilename
index=sysmon sourcetype="XmlWinEventLog" EventCode=7 ImageLoaded="*\msimg32.dll"
| search NOT Image="*\System32\*" NOT Image="*\SysWOW64\*"
| stats count by Computer, Image, ImageLoaded, Hashes
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\psexec*"
| stats count by Computer, Image, CommandLine, User
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (Image="*\rclone.exe" OR CommandLine="*rclone*")
| stats count by Computer, Image, CommandLine, ParentImage
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\wbadmin.exe" CommandLine="*delete*"
| stats count by Computer, Image, CommandLine, User
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\rdpclip.exe"
| stats count by Computer, Image, CommandLine, ParentImage
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\iexplore.exe"
| stats count by Computer, Image, CommandLine, ParentImage
index=sysmon sourcetype="XmlWinEventLog" EventCode=13 TargetObject="*Control\\WMI\\Autologger\\ReadyBoot*"
| stats count by Computer, TargetObject, Details, Image
index=sysmon sourcetype="XmlWinEventLog" EventCode=12 OR EventCode=13 TargetObject="*Uninstall\\Endpoint*"
| stats count by Computer, TargetObject, EventCode, Image
index=sysmon sourcetype="XmlWinEventLog" EventCode=13 TargetObject="*ControlSet001\\Services\\msiserver*"
| stats count by Computer, TargetObject, Details, Image
index=corelight sourcetype="corelight_dns" query="*z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid*"
| stats count by id.orig_h, query
index=corelight sourcetype="corelight_dns" query="*3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd*"
| stats count by id.orig_h, query
YARA Rules
HUNT_DragonForce_Ransomware_Hashes: Detects DragonForce ransomware samples based on known SHA256 hashes from Resecurity analysis
rule HUNT_DragonForce_Ransomware_Hashes
{
meta:
author = "RedSheepSec"
description = "Detects DragonForce ransomware samples by known SHA256 hashes"
date = "2026-10-02"
reference = "https://www.resecurity.com/blog/article/dragonforce-ransomware-reverse-engineering-report"
threat_actor = "DragonForce"
severity = "critical"
condition:
hash.sha256(0, filesize) == "b9bba02d18bacc4bc8d9e4f70657d381568075590cc9d0e7590327d854224b32" or
hash.sha256(0, filesize) == "ba1be94550898eedb10eb73cb5383a2d1050e96ec4df8e0bf680d3e76a9e2429" or
hash.sha256(0, filesize) == "d626eb0565fac677fdc13fb0555967dc31e600c74fbbd110b744f8e3a59dd3f9" or
hash.sha256(0, filesize) == "1250ba6f25fd60077f698a2617c15f89d58c1867339bfd9ee8ab19ce9943304b" or
hash.sha256(0, filesize) == "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507" or
hash.sha256(0, filesize) == "a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91" or
hash.sha256(0, filesize) == "9479a5dc61284ccc3f063ebb38da9f63400d8b25d8bca8d04b1832f02fac24de" or
hash.sha256(0, filesize) == "330730d65548d621d46ed9db939c434bc54cada516472ebef0a00422a5ed5819" or
hash.sha256(0, filesize) == "feab413f86532812efc606c3b3224b7c7080ae4aa167836d7233c262985f888c" or
hash.sha256(0, filesize) == "07ab218d5c865cb4fe78353340ab923e24a1f2881ec7206520651c5246b1a492"
}
HUNT_Gentlemen_Ransomware_Hashes: Detects The Gentlemen RaaS ransomware samples based on known SHA256 hashes from Group-IB analysis
rule HUNT_Gentlemen_Ransomware_Hashes
{
meta:
author = "RedSheepSec"
description = "Detects The Gentlemen RaaS ransomware samples by known SHA256 hashes"
date = "2026-10-02"
reference = "https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/"
threat_actor = "The Gentlemen"
severity = "critical"
condition:
hash.sha256(0, filesize) == "51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2" or
hash.sha256(0, filesize) == "3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235" or
hash.sha256(0, filesize) == "7e366683f1d175278feefaaa35d87e87076931974506b9f373a775a428c28f10"
}
HUNT_Gentlemen_Ransom_Note: Detects The Gentlemen ransomware ransom note file and associated artifact strings
rule HUNT_Gentlemen_Ransom_Note
{
meta:
author = "RedSheepSec"
description = "Detects The Gentlemen ransomware ransom note and associated strings"
date = "2026-10-02"
reference = "https://ransom-isac.org/blog/the-gentlemen-leak-analysis/"
threat_actor = "The Gentlemen"
severity = "high"
strings:
$note_name = "README-GENTLEMEN" ascii wide nocase
$s1 = "avastrclone" ascii wide nocase
$s2 = "GentleKiller" ascii wide nocase
$s3 = "Hastalamuerte" ascii wide nocase
condition:
any of them
}
HUNT_BYOVD_Vulnerable_Drivers: Detects vulnerable driver files used by Qilin, The Gentlemen, and DragonForce for BYOVD attacks
rule HUNT_BYOVD_Vulnerable_Drivers
{
meta:
author = "RedSheepSec"
description = "Detects vulnerable driver filenames used in BYOVD attacks by healthcare-targeting RaaS groups"
date = "2026-10-02"
threat_actor = "Qilin, The Gentlemen, DragonForce"
severity = "high"
strings:
$d1 = "ThrottleBlood.sys" ascii wide nocase
$d2 = "viragt64.sys" ascii wide nocase
$d3 = "K7RKScan.sys" ascii wide nocase
$d4 = "rwdrv.sys" ascii wide nocase
$d5 = "hlpdrv.sys" ascii wide nocase
condition:
any of them
}
HUNT_Qilin_DLL_Sideload: Detects Qilin DLL sideloading artifacts (upd.exe loading avupdate.dll)
rule HUNT_Qilin_DLL_Sideload
{
meta:
author = "RedSheepSec"
description = "Detects filenames associated with Qilin DLL sideloading technique"
date = "2026-10-02"
reference = "https://blackpointcyber.com/wp-content/uploads/2026/01/Qilin.pdf"
threat_actor = "Qilin"
severity = "high"
strings:
$loader = "upd.exe" ascii wide nocase
$payload = "avupdate.dll" ascii wide nocase
$scanner = "IPScanner.ps1" ascii wide nocase
$ransomware = "main.exe" ascii wide
condition:
2 of them
}
Suricata Rules
SID 2026001: Detects outbound connection to Qilin ransomware infrastructure IP 31.41.244.100
alert ip $HOME_NET any -> 31.41.244.100 any (msg:"HUNT Qilin Ransomware C2 IP 31.41.244.100"; classtype:trojan-activity; sid:2026001; rev:1; metadata:created_at 2026_10_02, threat_actor Qilin;)
SID 2026002: Detects outbound connection to DragonForce tool download IP 192.36.27.51
alert ip $HOME_NET any -> 192.36.27.51 any (msg:"HUNT DragonForce Backdoor Tool Download IP 192.36.27.51"; classtype:trojan-activity; sid:2026002; rev:1; metadata:created_at 2026_10_02, threat_actor DragonForce;)
SID 2026003: Detects outbound connection to DragonForce infrastructure IP 45.135.232.195
alert ip $HOME_NET any -> 45.135.232.195 any (msg:"HUNT DragonForce Infrastructure IP 45.135.232.195"; classtype:trojan-activity; sid:2026003; rev:1; metadata:created_at 2026_10_02, threat_actor DragonForce;)
SID 2026004: Detects outbound connection to DragonForce C2 IP 2.147.68.96
alert ip $HOME_NET any -> 2.147.68.96 any (msg:"HUNT DragonForce Ransomware C2 IP 2.147.68.96"; classtype:trojan-activity; sid:2026004; rev:1; metadata:created_at 2026_10_02, threat_actor DragonForce;)
SID 2026005: Detects outbound connection to DragonForce C2 IP 185.59.221.75
alert ip $HOME_NET any -> 185.59.221.75 any (msg:"HUNT DragonForce Ransomware C2 IP 185.59.221.75"; classtype:trojan-activity; sid:2026005; rev:1; metadata:created_at 2026_10_02, threat_actor DragonForce;)
SID 2026006: Detects outbound connection to DragonForce C2 IP 69.4.234.20
alert ip $HOME_NET any -> 69.4.234.20 any (msg:"HUNT DragonForce Ransomware C2 IP 69.4.234.20"; classtype:trojan-activity; sid:2026006; rev:1; metadata:created_at 2026_10_02, threat_actor DragonForce;)
SID 2026007: Detects Rclone user-agent in HTTP traffic indicating potential data exfiltration
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"HUNT Rclone User-Agent Detected - Potential Data Exfiltration"; flow:to_server,established; content:"rclone/"; http_user_agent; classtype:policy-violation; sid:2026007; rev:1; metadata:created_at 2026_10_02, threat_actor The_Gentlemen;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon EventID 6 (Driver Loaded) | T1562.001 | Critical for BYOVD detection. Ensure Sysmon is deployed with driver load logging enabled across all Windows endpoints. Driver allowlisting configuration is recommended. |
| Sysmon EventID 10 (Process Access) | T1003.001 | Required for LSASS credential dumping detection. Must be configured to log process access events targeting lsass.exe. High volume; tune carefully. |
| Sysmon EventID 1 (Process Create) | T1059.001, T1059.003, T1490, T1570, T1569.002, T1041 | Foundation for process execution monitoring. Ensure command line logging is enabled. Required for detecting PsExec, Rclone, vssadmin, wbadmin, and ransomware executable launches. |
| Sysmon EventID 11 (File Create) | T1486 | Required for detecting ransom note file creation. Configure to log file creation events in critical directories. |
| Sysmon EventID 13 (Registry Value Set) | T1047, T1562.001 | Required for detecting WMI Autologger tampering and EDR uninstallation via registry manipulation by The Gentlemen. |
| Sysmon EventID 7 (Image Loaded / DLL Load) | T1574.002 | Required for detecting DLL sideloading (avupdate.dll, msimg32.dll) used by Qilin. High volume; configure with path-based filters. |
| PowerShell ScriptBlock Logging (EventID 4104) | T1059.001 | Required for detecting IPScanner.ps1 and other PowerShell-based reconnaissance. Enable via Group Policy: Administrative Templates > Windows Components > PowerShell > Turn on Script Block Logging. |
| Windows Security EventID 5136 (AD Object Modified) | T1059.001, T1059.003 | Required for detecting GPO modifications that deploy malicious scripts to SYSVOL. Enable Advanced Audit Policy: DS Access > Audit Directory Service Changes. |
| Windows Security EventID 7045 (Service Installed) | T1569.002 | Required for detecting malicious service creation used by Qilin for execution. Available in the System event log by default. |
| PAN Firewall Logs | T1190, T1133 | Required for network-level IOC matching against known C2 IPs and for detecting exploitation attempts against FortiOS/FortiProxy. Both traffic and threat log sourcetypes are needed. |
| CrowdStrike EDR | T1566, T1562.001 | Provides detection coverage for phishing-based initial access and EDR tampering alerts. Verify that CrowdStrike detections are forwarding to Splunk via the crowdstrike index. |
| Corelight / Zeek Network Metadata | T1041, T1190 | Required for detecting anomalous outbound data transfers (Rclone exfiltration), DNS queries to .onion domains, and network-level IOC sweeps. |
| VMware ESXi Host Logs | T1675 | Required for detecting ESXi administration command abuse by Qilin. Verify that esxlog sourcetypes are forwarding to the linux-server index. |
Mitigations & Recommendations
Curated baseline: LockBit; library archetype
Established mitigations (curated):
- Execute all steps from Ransomware archetype containment (network isolation, backup protection, krbtgt reset, etc.).
- Block CISA-published LockBit C2 and exfil IPs/domains at perimeter.
- If Citrix ADC is deployed and Citrix Bleed is the vector: invalidate ALL ADC sessions and rotate session keys.
- Block MegaSync / rclone / StealBit process execution via EDR or AppLocker policy.
- Hunt peers of patient zero for LockBit precursor (commodity loader like Qakbot, IcedID, Bumblebee).
Established detection guidance (curated):
- Confirm LockBit by matching ransom note filename, wallpaper text, or encrypted file extension against CISA / vendor IOC list.
- Determine affiliate initial access vector: exploited edge CVE, phished credentials, brute-forced RDP, or IAB handoff.
- Scan for StealBit exfil tool and rclone misuse.
- Check for shadow copy deletion and recovery-disabling commands (shared with all ransomware but especially consistent for LockBit).
- Citrix Bleed session hijack hunt (if Citrix ADC/NetScaler is deployed).
- LockBit-specific service termination list: identify stopped services that LockBit kills pre-encryption.
Net-new from this incident:
- Deploy all Sigma rules and Splunk queries from this report across production Splunk instances, with Sysmon EventID 6 (BYOVD driver load) and EventID 10 (LSASS access) detections prioritized as critical.
- Patch all FortiOS and FortiProxy deployments against CVE-2024-55591 immediately. Review FortiOS authentication logs for the past 90 days for anomalous admin-level session creation from external IP addresses.
- Investigate any VPN appliance for CVE-2026-50751 exposure. Contact the appliance vendor for patch availability and apply compensating controls (restrict management interface access, enable MFA) if patches are not yet available.
- Block the 6 verified C2 IP addresses (31.41.244.100, 192.36.27.51, 45.135.232.195, 2.147.68.96, 185.59.221.75, 69.4.234.20) at the perimeter firewall and deploy the provided Suricata rules to IDS/IPS sensors.
- Deploy the 5 YARA rules to file scanning infrastructure, malware sandboxes, and endpoint scanning tools to detect DragonForce samples, Gentlemen ransomware binaries, BYOVD driver files, and Qilin DLL sideloading artifacts.
- Block unauthorized Rclone execution via application allowlisting. Rclone is not an authorized tool in most healthcare/DoD environments; any execution should trigger an alert regardless of filename.
- Conduct a third-party vendor risk assessment focused on EHR, medical billing, and data migration vendors, given the 35% increase in ransomware attacks against healthcare business associates. Verify that business associates have documented incident response plans and security controls.
- Enable Windows Credential Guard or LSASS RunAsPPL on all domain controllers and high-value servers to mitigate LSASS credential dumping.
- Implement driver-load allowlisting via Windows Defender Application Control (WDAC) or equivalent to prevent unauthorized kernel-mode drivers from loading, addressing the BYOVD technique used by all three groups.
- Monitor Microsoft Teams traffic patterns for anomalous session durations and data volumes that could indicate DragonForce Backdoor.Turn C2 tunneling. Coordinate with network security teams to evaluate TLS inspection capabilities for this traffic.
Sources
- ITRC H1 2026 Data Breach Report: Mega-Breaches and Malicious Insiders
- ITRC Press Release: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year
- CybersecurityStats: ITRC H1 2026 Data Breach Report
- HIPAA Journal: ITRC H1 2026 Data Breach Report
- Comparitech: Healthcare Ransomware Roundup H1 2026
- UpGuard: Biggest Data Breaches in the US
- Proven Data: Qilin Ransomware
- Adaptive Security: Qilin Ransomware
- Dexpose: Qilin Ransomware
- Blackpoint Cyber: Qilin Ransomware Technical Report
- Check Point: The Gentlemen Ransomware Threat
- CYFIRMA: Weekly Intelligence Report Sep 25, 2026
- Security Arsenal: The Gentlemen Ransomware Gang
- Rescana: Ransomware Attacks in Japan H1 2026
- ShieldWorkz: The Gentlemen Ransomware Threat Intelligence
- Dexpose: DragonForce Ransomware
- Decryption Digest: DragonForce Backdoor.Turn Microsoft Teams C2
- Ransomware.live: DragonForce Group Page
- Scott Helme: The Instructure Canvas Breach 2026
- Penligent: Canvas Cyber Security Incident
- RedRiver: The Canvas Hack
- Tech-Insider: Instructure Canvas ShinyHunters Breach
- Centrexit: Five Healthcare Ransomware Breaches
- Tech-Insider: Interim HealthCare Ransomware GENESIS Attack
- Dexpose: Chaos Ransomware Strikes Carolina Asthma & Allergy Center
- Shattered: Astrana Health Data Breach SEC Filing
- SWK Tech: Cybersecurity News Recap September 2026
- Tech-Insider: Aesto Health Data Breach 9.5 Million Patients
- StingRAI: Healthcare Data Breach Statistics 2026
- DeepStrike: Healthcare Cybersecurity Statistics
- HIPAA Journal: Healthcare Data Breach Statistics
- FaxSipIt: HIPAA Violation Statistics
- HIPAA Journal: April 2026 Healthcare Data Breach Report
- FaxSipIt: Healthcare Data Breach Statistics
- Resecurity: DragonForce Ransomware Reverse Engineering Report
- Group-IB: Hastalamuerte - The Gentlemen RaaS TTPs
- Blackpoint Cyber: DragonForce Technical Report
- NetManageIT: Japanese Ransomware - The Gentlemen and Qilin 2026
- Ransom-ISAC: The Gentlemen Leak Analysis