Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Qilin Ransomware

117
Global rank
184 infographic chevron month
Month rank
178 infographic chevron week
Week rank
0
IOCs

Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.

Ransomware
Type
Unknown
Origin
1 July, 2022
First seen
22 July, 2026
Last seen

How to analyze Qilin Ransomware with ANY.RUN

Type
Unknown
Origin
1 July, 2022
First seen
22 July, 2026
Last seen

IOCs

IP addresses
172.211.123.248
23.11.40.157
23.52.181.141
52.110.4.34
48.209.138.168
204.79.197.203
23.48.23.38
48.192.1.64
40.126.31.1
184.86.251.16
20.190.159.64
23.52.181.212
92.123.104.52
172.178.240.162
48.209.133.15
135.232.92.97
74.178.76.128
172.211.123.250
23.48.23.166
48.209.138.189
Hashes
9c08972e19fd9358f5d968908a63baa283a4e20cdfc6f9f3645e60002b6c4e10
c9707a3bc0f177e1d1a5587c61699975b1153406962d187c9a732f97d8f867c5
ed4282fe0cd8868f943b26bf2dc411c01abe00fc918aabd8c04167c7b46f0ccc
f26c3060239d6135cfa97d12b83084d3b3ea5094da32eff85dc02540bce43c29
6606e207bbb2ce23bb227d4884ee89ee9b07096ea2bf6dc720037c6aec8454d2
670e1b06c2071725c818cb508720aa1a92d273b26ab3a07f4c0d558bdc13a814
23f848b4fbb64edbf8f1968c3e37eff81e4f53d54dc375183bc2dd34ab7cde73
0050b9539af89481b14d25f7b34259943a304f2397751e36ade9c10ffd0067a8
61f7aa918b55238278a1666cb723df9e3639d229d1027611e02ae3808ede33ed
b64ed3edd22b4376a8895661fff669fde9410829e7af9100cd46475f7b1d9870
ba1230ad22bd7440da30813aead3d738325fcfb65073cd31989cd1b4a1f54449
51e995160c3ddf7390b02f77c8c5545cca0e2df5a7b972f498a740de5e609feb
eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
89f2a5c6be1e70b3d895318fdd618506b8c0e9a63b6a1a4055dff4abdc89f18a
93ff42e60c442559119478cca468b190bade2b030e638788c4400c01f5336958
41ad1a04ca27a7959579e87fbbda87c93099616a64a0e66260c983381c5570d1
2a234b5aa20c3faecf725bbb54fb33f3d94543f78fa7045408e905593e49960a
5604f629523125904909547a97f3cdb5dbfe33b39878bad77534de0c3c034387
8a9a103bc417dede9f6946d9033487c410937e1761d93c358c1600b82f0a711f
e28d4e46e5d10b5fdcf0292f91e8fd767e33473116247cd5d577e4554d7a4c0c
Domains
go.microsoft.com
oneocsp.microsoft.com
client.wns.windows.com
google.com
settings-win.data.microsoft.com
slscr.update.microsoft.com
ocsp.digicert.com
www.microsoft.com
login.live.com
www.bing.com
self.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
officeclient.microsoft.com
activation-v2.sls.microsoft.com
ecs.office.com
crl.microsoft.com
watson.events.data.microsoft.com
nexusrules.officeapps.live.com
arc.msn.com
fd.api.iris.microsoft.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/rp/anzunpnvy0ol0xwxs0rljxjjluo.br.js
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

What is Qilin Ransomware?

Qilin operates as a Ransomware-as-a-Service (RaaS) platform, providing criminal affiliates with sophisticated tools and infrastructure to conduct ransomware attacks. Gained popularity by late 2023 and has since become increasingly sophisticated in its operations. Amassed over $50 million in ransom payments in 2024 alone. Ranked as the most prevalent ransomware in public threat intelligence reports by 2025.

Last year, cybersecurity company Halcyon discovered an improved version of the ransomware that it named Qilin.B. This newer variant demonstrates enhanced capabilities in terms of encryption speed, evasion techniques, and payload delivery mechanisms. What sets Qilin apart from other ransomware families is its focus on operational efficiency and stealth. Once Qilin has gained initial access, it employs advanced obfuscation techniques to evade detection. The ransomware code is packed, disguising its true nature to avoid static analysis.
The group has also demonstrated remarkable adaptability, quickly capitalizing on disruptions to competing ransomware operations to expand their affiliate base and market presence.

Qilin is written in Rust and Go, enabling cross-platform attacks against both Windows and Linux environments. Qilin’s modular design allows attackers to customize payloads, set encryption methods, and configure ransom notes. The ransomware has a professionalized infrastructure, including a data leak site where stolen information is published if victims refuse to pay.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Qilin Malware Victimology

Qilin targets a diverse range of organizations across multiple sectors, with a particular focus on high-value targets that are likely to pay substantial ransoms. In June 2025, the United States remained the primary target of ransomware attacks, recording 235 victims, far surpassing other nations. Canada (24), the United Kingdom (24), Germany (15), and Israel (13) also experienced notable activity.

The threat actors behind Qilin demonstrate a clear preference for:

  • Healthcare Organizations: Hospitals and medical facilities are frequent targets due to their critical nature and limited tolerance for downtime
  • Financial Services: Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications.
  • Manufacturing and Industrial Facilities: Critical infrastructure targets that cannot afford extended operational disruptions
  • Educational Institutions: Universities and school districts with valuable research data and personal information
  • Government Agencies: Local and regional government entities with sensitive citizen data
  • Professional Services: Law firms, consulting companies, and other service providers handling confidential client information

The targeting strategy appears to prioritize organizations in developed economies where cyber insurance coverage is common and ransom payment capabilities are higher. The geographical distribution reflects this focus, with North America and Europe representing the majority of victims.

Qilin Ransomware Attack Chain and Technical Details

One of Qilin’s features is the requirement to input a unique password, passed as a command-line argument when launching the executable file, which enhances its protection against analysis.

The community of about half a million users of ANY.RUN’s Interactive Sandbox has submitted and analyzed a number of Qilin’s samples featuring this password input. Let’s view an analysis with a correctly entered password.
View Qilin detonated in the Sandbox

Qilin analysis in Interactive Sandbox Qilin sample analysis in the Interactive Sandbox

Qilin employs commands to manipulate symbolic links in Windows, altering the system's behavior regarding the handling of symbolic links. The commands used are:

fsutil behavior set SymlinkEvaluation R2R:1
fsutil behavior set SymlinkEvaluation R2L:1

Qilin link commands Qilin link commands in the process tree in the Interactive Sandbox

To conceal the traces of its activity, Qilin clears system logs, making it difficult to detect and analyze the attack, using a PowerShell script:

Qilin PowerShell script Qilin log wiping PowerShell script

Subsequently, the malware destroys Volume Shadow Copies (VSS) to prevent data recovery without paying the ransom. To do this, the ransomware executes a sequence of commands that manipulate the Volume Shadow Copy Service and deletes all existing snapshots. The commands used are:

net start vss wmic service where name='vss' call ChangeStartMode Manual vssadmin.exe delete shadows /all /quiet net stop vss wmic service where name='vss' call ChangeStartMode Disabled

Qilin also uses commands to prevent failures in cluster services and to propagate through a domain environment via Active Directory (AD). These commands include:

Stop-Cluster -Force

Import-Module ActiveDirectory ; Get-ADComputer -Filter * | Select-Object -ExpandProperty DNSHostName

ServerManagerCmd.exe -i RSAT-AD-PowerShell ; Install-WindowsFeature RSAT-AD-PowerShell ; Add-WindowsCapability -Online -Name 'RSAT.ActiveDirectory.DS-LDS.Tools~0.0.1.0'

Qilin encrypts files, appending an extension composed of a unique set of random characters for each attack. This extension is also included in the name of the ransom note file left in the infected directories.

How Qilin Ransomware Generally Functions

Qilin operates through a sophisticated technical architecture designed for maximum effectiveness and stealth. Adversaries operating the Qilin ransomware adopt a multi-pronged strategy to breach target networks, relying on both misconfigurations and software vulnerabilities.

Common Entry Points:

  • Vulnerability exploitation
  • Exploitation of unpatched VPN appliances and firewalls
  • Compromise of Remote Desktop Protocol (RDP) services
  • Phishing campaigns targeting employee credentials
  • Supply chain compromises through trusted vendor access
  • Exploitation of public-facing web applications
  • Abuse of legitimate remote access tools

Lateral Movement Techniques:

  • Once inside a network, Qilin employs various techniques to spread:
  • Credential dumping from compromised systems
  • Pass-the-hash and pass-the-ticket attacks
  • Exploitation of Windows vulnerabilities for privilege escalation
  • Living-off-the-land techniques using legitimate system tools
  • Network scanning to identify additional targets
  • Abuse of administrative tools like PowerShell and WMI

Network Persistence:

  • Creation of backdoor accounts and hidden administrative access
  • Installation of remote access tools for persistent connectivity
  • Modification of security policies to maintain access
  • Deployment of additional payloads for redundant access

Advanced Evasion Techniques:

Further, Qilin uses various code obfuscation methods, such as renaming functions, altering control flows, and encrypting strings, to complicate reverse engineering efforts. This also makes Qilin difficult to detect with IOCs located further along the killchain.

Anti-Analysis Mechanisms:

To further hinder analysis, Qilin integrates anti-analysis mechanisms designed to identify and disable debugging and sandbox environments. It actively scans for virtual machines and common sandbox artifacts to evade dynamic analysis, preventing security researchers from closely examining its behavior.

Encryption Implementation:

The ransomware implements robust encryption algorithms with the following characteristics:

  • Uses industry-standard AES-256 encryption for file encryption
  • Employs RSA public-key cryptography for key protection
  • Generates unique encryption keys for each infected system
  • Implements secure key management to prevent unauthorized decryption

Communication Infrastructure:

  • Utilizes Tor networks for command and control communications
  • Implements secure communication protocols to protect operator anonymity
  • Maintains redundant infrastructure to ensure operational continuity
  • Uses cryptocurrency payment systems for ransom collection

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

What Qilin Malware Can Do to an Endpoint Device

When Qilin successfully infiltrates a device, it implements a multi-stage attack process designed to maximize damage while evading detection:

Initial Compromise and Persistence:

  • Establishes persistence mechanisms through registry modifications and scheduled tasks
  • Creates backup access points to maintain access even if primary entry vectors are discovered
  • Disables Windows Defender and other security solutions through privilege escalation

System Manipulation:

Using renamed binaries like upd.exe (a spoof of legitimate AV updaters), Qilin ransomware disables EDR, clears logs, and bypasses detection. The malware might even exploit outdated Carbon Black Cloud sensors to remain hidden.

Credential Harvesting:

Once elevated, Qilin dumps LSASS memory and extracts credentials to facilitate lateral movement across the network. This process allows the ransomware to escalate privileges and access additional systems.

Data Encryption Process:

  • Encrypts files using strong cryptographic algorithms, typically AES-256 with RSA key protection
  • Targets specific file types while avoiding system files necessary for basic OS functionality
  • Appends custom file extensions to encrypted files
  • Drops ransom notes in multiple locations across the infected system
  • Modifies desktop wallpaper to display ransom information

System Degradation:

  • Disables system recovery features including Windows System Restore
  • Deletes shadow copies and backup files to prevent easy recovery
  • Clears event logs to hinder forensic analysis
  • May corrupt or delete system files to increase recovery complexity.

Notable Qilin Attacks

The scope of Qilin's operations has grown dramatically. investigated network artifacts related to Qilin and identified three probable cases of the ransomware across the Darktrace customer base between June 2022 and May 2024. However, by 2025, the frequency had increased exponentially, with the group claiming dozens of victims monthly.

A Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications. This incident underscores the persistent threat Qilin poses to financial services organizations.

The Qilin ransomware group launched attacks exploiting Fortinet vulnerabilities CVE-2024-21762 and CVE-2024-55591 between May and June 2025. These attacks demonstrated Qilin's ability to target critical infrastructure through systematic exploitation of network security appliances.

Multiple healthcare organizations have fallen victim to Qilin attacks, resulting in cancelled surgeries, delayed medical procedures, and compromised patient care. These attacks highlight the life-threatening potential of ransomware when targeting critical infrastructure.

Several universities and school districts have been targeted, resulting in exposure of student records, research data, and administrative systems. These attacks often occur during critical periods such as registration or examination periods to maximize pressure for ransom payment.

Gathering Threat Intelligence on Qilin Ransomware

Effectively countering such complex threats as Qilin is impossible without access to a large volume of detailed up-to-date threat Intelligence. It fuels:

  • Proactive detection based on studying the malware's behavior before it attacks corporate systems.
  • Creating High-Quality Signatures and Correlation Rules: Understanding specific commands, scripts, and sequences of actions enables the configuration of security systems (SIEM, EDR) for precise attack detection.
  • Investigating Incidents: TI data helps analysts quickly understand the scope and methods of an attack, identify affected systems, and take appropriate response actions.

Indicators of Compromise (IOCs) include:

  • Presence of unusual Rust/Go executables.
  • Suspicious processes terminating backups or security tools.
  • Encrypted files with unique extensions set by affiliates.
  • Outbound connections to Tor-based C2 servers.
  • Ransom notes dropped across multiple directories.

Behavioral detection (via EDR/XDR) is critical: look for privilege escalation, mass file encryption, and registry tampering.

Start using Threat Intelligence Lookup for free: collect IOCs, browse sandbox detonations.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deeper into contextual data on Qilin. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"qilin"

Qilin samples found via Threat Intelligence Lookup Qilin sample analyses found via Threat Intelligence Lookup

To find Qilin samples with the above-mentioned password submitting, use an additional search parameter:

threatName:"Qilin" and commandLine:"password"

Qilin samples with password found via Threat Intelligence Lookup Qilin samples with password analyzed in the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Qilin is now one of the most prominent ransomware threats globally. Its rapid rise, adoption by advanced threat actors, and the growing number of victims in late 2024 and early 2025 point to sustained activity well into the years ahead. The threat is likely to persist and potentially intensify, making preparation and prevention more critical than ever.

The ransomware family represents a significant evolution in cybercriminal sophistication, combining advanced technical capabilities with effective business operations to create a formidable threat.

Although Qilin follows a typical ransomware attack chain, its success lies in the effectiveness of its evasion strategies, allowing it to execute attacks with minimal detection until the final encryption phase.

The fight against Qilin ransomware is not just a technical challenge but also a strategic business imperative. Organizations that invest in comprehensive cybersecurity programs, maintain current threat intelligence, and prepare for incident response will be better positioned to resist this sophisticated threat and protect their critical assets and operations.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for quick detection and response.

HAVE A LOOK AT

EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More