Uncovering Qilin attack methods exposed through multiple cases
Oct. 27, 2025, 10:34 a.m.
Description
The ransomware group Qilin has been highly active in 2025, publishing over 40 victim cases per month on its leak site. Manufacturing, professional services, and wholesale trade are the most affected sectors. Attackers likely originate from Eastern Europe or Russian-speaking regions. They use tools like Cyberduck for data exfiltration and leverage notepad.exe and mspaint.exe to view sensitive information. The attack flow includes initial VPN access, reconnaissance, credential theft, lateral movement, and ransomware deployment. Two encryptors are often used: one spread via PsExec and another targeting network shares. The ransomware encrypts files, deletes backups, and leaves ransom notes. Persistence is achieved through scheduled tasks and registry modifications.
Tags
Date
- Created: Oct. 27, 2025, 8:11 a.m.
- Published: Oct. 27, 2025, 8:11 a.m.
- Modified: Oct. 27, 2025, 10:34 a.m.
Indicators
- e705f69afd97f343f3c1f2bc6027d30935a0bfd29ff025c563f6f8c1f9a7478e
- e129dd5cc80f39b24db489df999c847335d169910bd966814d2f81b0b1bbc365
- dd29138bf369863c33402a3fc995458ab5fc015a13a9378022131ab31d940c9f
- dbe9ed8e8e8cdff3670e7205cb9f11b5a0fa9d1983a6c6bab67527d8775c4ffd
- d1347f4dccebf2fcd672dcef9c66c91b9d3f12b9881e3e390626927718fda616
- a068f595472c4f94baf1c2a8fba6831a327514e24ec4b38e1eee2cf1646b1591
- 792182b7c5a56e5ccefd32073dc374e66c6a4e7981075e3804f49a276878e0fb
- 8fe746dd277e644fa0337db3394f0eadfafe57df029e13df9feef25c536adf4d
- 38ddde36929a2ddf13b1844973550072c41004187eaa2456f86e20aa93036b18
- 6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc
- 912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9
- 85.239.34.91
- 86.106.85.36
- mimikatzlogs@anti.pm
- mimikatz@anti.pm
- regsvchst.com
- holapor67.top
Additional Informations
- Wholesale trade
- Professional and scientific services
- Construction
- Retail
- Healthcare
- Education
- Finance
- Manufacturing
- Canada
- France
- Germany
- United Kingdom of Great Britain and Northern Ireland
- United States of America