Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Qilin Ransomware

124
Global rank
116 infographic chevron month
Month rank
128 infographic chevron week
Week rank

Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.

Ransomware
Type
Unknown
Origin
1 July, 2022
First seen
10 September, 2026
Last seen

How to analyze Qilin Ransomware with ANY.RUN

Type
Unknown
Origin
1 July, 2022
First seen
10 September, 2026
Last seen

IOCs

IP addresses
104.18.19.203
48.209.138.189
23.36.163.33
40.126.31.71
184.31.95.119
52.168.117.175
204.79.197.203
2.16.106.30
74.178.240.61
23.11.41.157
74.178.240.51
23.194.190.166
52.111.231.8
2.23.246.9
52.110.17.202
48.192.1.65
2.16.106.34
23.59.18.102
23.194.190.158
104.102.63.189
Hashes
bbe0867984fd439067703f307018f96ea37fda8f8b79fc12843d6068e77dcc32
93fa329ba9ef75af1d19df29a2b933bc1eb83336703bbdd3cbc60946a9f668b9
2de8631b2a69ae54c962af917bb57a9ae06949e606da5088f256b866df8cdaba
95e9db2278364c40d924d624dc9865105d277c22ddee7b3f459b069338b8c56a
6a5cb307510ec859954146b9b86e3884fa5b108ee3701a21427d0efc883352b9
488a401645c6030b741d7e912aa55ad9ec6b219d36a3247332454c0de867b827
49ac386ee6d11314016f0990b0b9e95f8616dfa889f6cf131ba805132f16fc89
5dd9f78a898b6d956c245d82a1323d513411fa525edca0c6a30c2c5cff59794e
1be16fe0f1efb26b6da07fbeeb5f887df27433f353dfe7d2cfc3e052e4fcb0bd
49c1ce155440eaca41795e5308e625dd5e8f36ad71e5a2e9b3898b625b6022d8
0dfa017a86a8dd9c7b2f8a07af89f6e5a2dbacea8e0d2699b6176e055a8a1a15
5f03cf363d0cc6ea858035722c9ff5ad7290c72695eeb481d01492140011516a
77d9cddcdf03f2e1f02c73df3e6be331435fa58878d9f0e8835b858a1c4cd67a
66e889df958e14400e9be5874c02213de1e81003019103a7b12175e1d22474f8
3e4719c4eece8d4365a95aeef4f71526731435452a797144ec55cd98f50b0434
81ca6f630139d7bfc3efe130e031ab1114a699e57be34bd64a1930528800bd92
438a487d96c184aafaf90bf796dfb7b551fbaec22e8b9ef432eb3675b8c814cf
61fea6de5fff201dcdb338add34ffc820f888ab0a60c7b9f3959d55e8fdba0c2
b452ba00f4971736a7eadcf2187b7c008a145e84fb43b046594807625c065640
8a2cedeec7ca8ac2691f024af0f453170e8b6647a9de382a9a82c9ac8ef73025
Domains
omex.cdn.office.net
odc.officeapps.live.com
crl.microsoft.com
fe3cr.delivery.mp.microsoft.com
self.events.data.microsoft.com
metadata.templates.cdn.office.net
ocsp.digicert.com
www.microsoft.com
messaging.engagement.office.com
editor.svc.cloud.microsoft
login.live.com
activation-v2.sls.microsoft.com
slscr.update.microsoft.com
roaming.svc.cloud.microsoft
createcatalog.public.onecdn.static.microsoft
nexusrules.officeapps.live.com
settings-win.data.microsoft.com
google.com
messaging.lifecycle.office.com
officeclient.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
https://ecs.office.com/config/v2/office/word/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=word&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=winword.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7b40faa407-11c2-441b-8f4e-32e27efd933a%7d&labmachine=false
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://roaming.svc.cloud.microsoft/rs/roamingsoapservice.svc
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://fs.microsoft.com/fs/4.42/flatfontassets.pkg
https://messaging.engagement.office.com/campaignmetadataaggregator?app=0&platform=10&ofc_channel=cc&ofc_audience=production&ofc_flights=ofsh6c2b1tla1a31%3bofcrui4yvdulbf31%3bofhpex3jznepoo31%3bofjhlwlmoc1pz531&ver=16.0.16026.20002&hwid=04111-083-043729aed3&osversion=10.0.19045&country=us&locale=en-us&ofc_licensecategory=6&ofc_licensesku=professional2019retail&contenttype=campaigncontent
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 382
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 642
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 2232
comments 0

What is Qilin Ransomware?

Qilin operates as a Ransomware-as-a-Service (RaaS) platform, providing criminal affiliates with sophisticated tools and infrastructure to conduct ransomware attacks. Gained popularity by late 2023 and has since become increasingly sophisticated in its operations. Amassed over $50 million in ransom payments in 2024 alone. Ranked as the most prevalent ransomware in public threat intelligence reports by 2025.

Last year, cybersecurity company Halcyon discovered an improved version of the ransomware that it named Qilin.B. This newer variant demonstrates enhanced capabilities in terms of encryption speed, evasion techniques, and payload delivery mechanisms. What sets Qilin apart from other ransomware families is its focus on operational efficiency and stealth. Once Qilin has gained initial access, it employs advanced obfuscation techniques to evade detection. The ransomware code is packed, disguising its true nature to avoid static analysis.
The group has also demonstrated remarkable adaptability, quickly capitalizing on disruptions to competing ransomware operations to expand their affiliate base and market presence.

Qilin is written in Rust and Go, enabling cross-platform attacks against both Windows and Linux environments. Qilin’s modular design allows attackers to customize payloads, set encryption methods, and configure ransom notes. The ransomware has a professionalized infrastructure, including a data leak site where stolen information is published if victims refuse to pay.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Qilin Malware Victimology

Qilin targets a diverse range of organizations across multiple sectors, with a particular focus on high-value targets that are likely to pay substantial ransoms. In June 2025, the United States remained the primary target of ransomware attacks, recording 235 victims, far surpassing other nations. Canada (24), the United Kingdom (24), Germany (15), and Israel (13) also experienced notable activity.

The threat actors behind Qilin demonstrate a clear preference for:

  • Healthcare Organizations: Hospitals and medical facilities are frequent targets due to their critical nature and limited tolerance for downtime
  • Financial Services: Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications.
  • Manufacturing and Industrial Facilities: Critical infrastructure targets that cannot afford extended operational disruptions
  • Educational Institutions: Universities and school districts with valuable research data and personal information
  • Government Agencies: Local and regional government entities with sensitive citizen data
  • Professional Services: Law firms, consulting companies, and other service providers handling confidential client information

The targeting strategy appears to prioritize organizations in developed economies where cyber insurance coverage is common and ransom payment capabilities are higher. The geographical distribution reflects this focus, with North America and Europe representing the majority of victims.

Qilin Ransomware Attack Chain and Technical Details

One of Qilin’s features is the requirement to input a unique password, passed as a command-line argument when launching the executable file, which enhances its protection against analysis.

The community of about half a million users of ANY.RUN’s Interactive Sandbox has submitted and analyzed a number of Qilin’s samples featuring this password input. Let’s view an analysis with a correctly entered password.
View Qilin detonated in the Sandbox

Qilin analysis in Interactive Sandbox Qilin sample analysis in the Interactive Sandbox

Qilin employs commands to manipulate symbolic links in Windows, altering the system's behavior regarding the handling of symbolic links. The commands used are:

fsutil behavior set SymlinkEvaluation R2R:1
fsutil behavior set SymlinkEvaluation R2L:1

Qilin link commands Qilin link commands in the process tree in the Interactive Sandbox

To conceal the traces of its activity, Qilin clears system logs, making it difficult to detect and analyze the attack, using a PowerShell script:

Qilin PowerShell script Qilin log wiping PowerShell script

Subsequently, the malware destroys Volume Shadow Copies (VSS) to prevent data recovery without paying the ransom. To do this, the ransomware executes a sequence of commands that manipulate the Volume Shadow Copy Service and deletes all existing snapshots. The commands used are:

net start vss wmic service where name='vss' call ChangeStartMode Manual vssadmin.exe delete shadows /all /quiet net stop vss wmic service where name='vss' call ChangeStartMode Disabled

Qilin also uses commands to prevent failures in cluster services and to propagate through a domain environment via Active Directory (AD). These commands include:

Stop-Cluster -Force

Import-Module ActiveDirectory ; Get-ADComputer -Filter * | Select-Object -ExpandProperty DNSHostName

ServerManagerCmd.exe -i RSAT-AD-PowerShell ; Install-WindowsFeature RSAT-AD-PowerShell ; Add-WindowsCapability -Online -Name 'RSAT.ActiveDirectory.DS-LDS.Tools~0.0.1.0'

Qilin encrypts files, appending an extension composed of a unique set of random characters for each attack. This extension is also included in the name of the ransom note file left in the infected directories.

How Qilin Ransomware Generally Functions

Qilin operates through a sophisticated technical architecture designed for maximum effectiveness and stealth. Adversaries operating the Qilin ransomware adopt a multi-pronged strategy to breach target networks, relying on both misconfigurations and software vulnerabilities.

Common Entry Points:

  • Vulnerability exploitation
  • Exploitation of unpatched VPN appliances and firewalls
  • Compromise of Remote Desktop Protocol (RDP) services
  • Phishing campaigns targeting employee credentials
  • Supply chain compromises through trusted vendor access
  • Exploitation of public-facing web applications
  • Abuse of legitimate remote access tools

Lateral Movement Techniques:

  • Once inside a network, Qilin employs various techniques to spread:
  • Credential dumping from compromised systems
  • Pass-the-hash and pass-the-ticket attacks
  • Exploitation of Windows vulnerabilities for privilege escalation
  • Living-off-the-land techniques using legitimate system tools
  • Network scanning to identify additional targets
  • Abuse of administrative tools like PowerShell and WMI

Network Persistence:

  • Creation of backdoor accounts and hidden administrative access
  • Installation of remote access tools for persistent connectivity
  • Modification of security policies to maintain access
  • Deployment of additional payloads for redundant access

Advanced Evasion Techniques:

Further, Qilin uses various code obfuscation methods, such as renaming functions, altering control flows, and encrypting strings, to complicate reverse engineering efforts. This also makes Qilin difficult to detect with IOCs located further along the killchain.

Anti-Analysis Mechanisms:

To further hinder analysis, Qilin integrates anti-analysis mechanisms designed to identify and disable debugging and sandbox environments. It actively scans for virtual machines and common sandbox artifacts to evade dynamic analysis, preventing security researchers from closely examining its behavior.

Encryption Implementation:

The ransomware implements robust encryption algorithms with the following characteristics:

  • Uses industry-standard AES-256 encryption for file encryption
  • Employs RSA public-key cryptography for key protection
  • Generates unique encryption keys for each infected system
  • Implements secure key management to prevent unauthorized decryption

Communication Infrastructure:

  • Utilizes Tor networks for command and control communications
  • Implements secure communication protocols to protect operator anonymity
  • Maintains redundant infrastructure to ensure operational continuity
  • Uses cryptocurrency payment systems for ransom collection

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

What Qilin Malware Can Do to an Endpoint Device

When Qilin successfully infiltrates a device, it implements a multi-stage attack process designed to maximize damage while evading detection:

Initial Compromise and Persistence:

  • Establishes persistence mechanisms through registry modifications and scheduled tasks
  • Creates backup access points to maintain access even if primary entry vectors are discovered
  • Disables Windows Defender and other security solutions through privilege escalation

System Manipulation:

Using renamed binaries like upd.exe (a spoof of legitimate AV updaters), Qilin ransomware disables EDR, clears logs, and bypasses detection. The malware might even exploit outdated Carbon Black Cloud sensors to remain hidden.

Credential Harvesting:

Once elevated, Qilin dumps LSASS memory and extracts credentials to facilitate lateral movement across the network. This process allows the ransomware to escalate privileges and access additional systems.

Data Encryption Process:

  • Encrypts files using strong cryptographic algorithms, typically AES-256 with RSA key protection
  • Targets specific file types while avoiding system files necessary for basic OS functionality
  • Appends custom file extensions to encrypted files
  • Drops ransom notes in multiple locations across the infected system
  • Modifies desktop wallpaper to display ransom information

System Degradation:

  • Disables system recovery features including Windows System Restore
  • Deletes shadow copies and backup files to prevent easy recovery
  • Clears event logs to hinder forensic analysis
  • May corrupt or delete system files to increase recovery complexity.

Notable Qilin Attacks

The scope of Qilin's operations has grown dramatically. investigated network artifacts related to Qilin and identified three probable cases of the ransomware across the Darktrace customer base between June 2022 and May 2024. However, by 2025, the frequency had increased exponentially, with the group claiming dozens of victims monthly.

A Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications. This incident underscores the persistent threat Qilin poses to financial services organizations.

The Qilin ransomware group launched attacks exploiting Fortinet vulnerabilities CVE-2024-21762 and CVE-2024-55591 between May and June 2025. These attacks demonstrated Qilin's ability to target critical infrastructure through systematic exploitation of network security appliances.

Multiple healthcare organizations have fallen victim to Qilin attacks, resulting in cancelled surgeries, delayed medical procedures, and compromised patient care. These attacks highlight the life-threatening potential of ransomware when targeting critical infrastructure.

Several universities and school districts have been targeted, resulting in exposure of student records, research data, and administrative systems. These attacks often occur during critical periods such as registration or examination periods to maximize pressure for ransom payment.

Gathering Threat Intelligence on Qilin Ransomware

Effectively countering such complex threats as Qilin is impossible without access to a large volume of detailed up-to-date threat Intelligence. It fuels:

  • Proactive detection based on studying the malware's behavior before it attacks corporate systems.
  • Creating High-Quality Signatures and Correlation Rules: Understanding specific commands, scripts, and sequences of actions enables the configuration of security systems (SIEM, EDR) for precise attack detection.
  • Investigating Incidents: TI data helps analysts quickly understand the scope and methods of an attack, identify affected systems, and take appropriate response actions.

Indicators of Compromise (IOCs) include:

  • Presence of unusual Rust/Go executables.
  • Suspicious processes terminating backups or security tools.
  • Encrypted files with unique extensions set by affiliates.
  • Outbound connections to Tor-based C2 servers.
  • Ransom notes dropped across multiple directories.

Behavioral detection (via EDR/XDR) is critical: look for privilege escalation, mass file encryption, and registry tampering.

Start using Threat Intelligence Lookup for free: collect IOCs, browse sandbox detonations.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deeper into contextual data on Qilin. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"qilin"

Qilin samples found via Threat Intelligence Lookup Qilin sample analyses found via Threat Intelligence Lookup

To find Qilin samples with the above-mentioned password submitting, use an additional search parameter:

threatName:"Qilin" and commandLine:"password"

Qilin samples with password found via Threat Intelligence Lookup Qilin samples with password analyzed in the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Qilin is now one of the most prominent ransomware threats globally. Its rapid rise, adoption by advanced threat actors, and the growing number of victims in late 2024 and early 2025 point to sustained activity well into the years ahead. The threat is likely to persist and potentially intensify, making preparation and prevention more critical than ever.

The ransomware family represents a significant evolution in cybercriminal sophistication, combining advanced technical capabilities with effective business operations to create a formidable threat.

Although Qilin follows a typical ransomware attack chain, its success lies in the effectiveness of its evasion strategies, allowing it to execute attacks with minimal detection until the final encryption phase.

The fight against Qilin ransomware is not just a technical challenge but also a strategic business imperative. Organizations that invest in comprehensive cybersecurity programs, maintain current threat intelligence, and prepare for incident response will be better positioned to resist this sophisticated threat and protect their critical assets and operations.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for quick detection and response.

HAVE A LOOK AT

Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More
UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More