Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Qilin Ransomware

130
Global rank
132 infographic chevron month
Month rank
180 infographic chevron week
Week rank

Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.

Ransomware
Type
Unknown
Origin
1 July, 2022
First seen
21 September, 2026
Last seen

How to analyze Qilin Ransomware with ANY.RUN

Type
Unknown
Origin
1 July, 2022
First seen
21 September, 2026
Last seen

IOCs

IP addresses
48.192.1.64
48.209.133.15
172.66.2.5
48.209.138.189
23.11.41.157
2.16.204.161
2.16.204.157
2.23.246.9
48.209.138.168
20.190.160.22
74.178.76.54
57.153.246.3
2.21.239.135
2.21.20.152
20.165.94.63
95.100.102.101
2.16.204.156
172.211.123.248
204.79.197.203
23.59.18.102
Hashes
907c48316ea3d9592204cc16c817530b7bdaeed7f04d32535dac66de3713202c
f607c25e731a913a804bde925a18e58cbeb103cd2f84b84e5fb114c75e3d9478
4d2b61ce656f8ad474d8d615fbd0f73aab52fb4509ae3ab0a9de5b69ba4a2bed
9b29b730780a1b555157d13ff8a546b471452f62527d1a3be40e5432b58303a8
5fbf21f77e57bf34030bbdf2a63f888f7263bd52680e36709715501857f4a174
bbe0867984fd439067703f307018f96ea37fda8f8b79fc12843d6068e77dcc32
93fa329ba9ef75af1d19df29a2b933bc1eb83336703bbdd3cbc60946a9f668b9
2de8631b2a69ae54c962af917bb57a9ae06949e606da5088f256b866df8cdaba
95e9db2278364c40d924d624dc9865105d277c22ddee7b3f459b069338b8c56a
6a5cb307510ec859954146b9b86e3884fa5b108ee3701a21427d0efc883352b9
488a401645c6030b741d7e912aa55ad9ec6b219d36a3247332454c0de867b827
49ac386ee6d11314016f0990b0b9e95f8616dfa889f6cf131ba805132f16fc89
5dd9f78a898b6d956c245d82a1323d513411fa525edca0c6a30c2c5cff59794e
1be16fe0f1efb26b6da07fbeeb5f887df27433f353dfe7d2cfc3e052e4fcb0bd
49c1ce155440eaca41795e5308e625dd5e8f36ad71e5a2e9b3898b625b6022d8
0dfa017a86a8dd9c7b2f8a07af89f6e5a2dbacea8e0d2699b6176e055a8a1a15
5f03cf363d0cc6ea858035722c9ff5ad7290c72695eeb481d01492140011516a
77d9cddcdf03f2e1f02c73df3e6be331435fa58878d9f0e8835b858a1c4cd67a
66e889df958e14400e9be5874c02213de1e81003019103a7b12175e1d22474f8
3e4719c4eece8d4365a95aeef4f71526731435452a797144ec55cd98f50b0434
Domains
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
oneocsp.microsoft.com
ocsp.digicert.com
go.microsoft.com
th.bing.com
login.live.com
www.bing.com
self.events.data.microsoft.com
crl.microsoft.com
settings-win.data.microsoft.com
www.microsoft.com
activation-v2.sls.microsoft.com
nexusrules.officeapps.live.com
google.com
client.wns.windows.com
omex.cdn.office.net
odc.officeapps.live.com
metadata.templates.cdn.office.net
messaging.engagement.office.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f21%2f2026%2c%206%3a32%3a01%20am
https://www.bing.com/dsb/scenario?name=trendingsearchwithcache&cc=us&setlang=en-us
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

What is Qilin Ransomware?

Qilin operates as a Ransomware-as-a-Service (RaaS) platform, providing criminal affiliates with sophisticated tools and infrastructure to conduct ransomware attacks. Gained popularity by late 2023 and has since become increasingly sophisticated in its operations. Amassed over $50 million in ransom payments in 2024 alone. Ranked as the most prevalent ransomware in public threat intelligence reports by 2025.

Last year, cybersecurity company Halcyon discovered an improved version of the ransomware that it named Qilin.B. This newer variant demonstrates enhanced capabilities in terms of encryption speed, evasion techniques, and payload delivery mechanisms. What sets Qilin apart from other ransomware families is its focus on operational efficiency and stealth. Once Qilin has gained initial access, it employs advanced obfuscation techniques to evade detection. The ransomware code is packed, disguising its true nature to avoid static analysis.
The group has also demonstrated remarkable adaptability, quickly capitalizing on disruptions to competing ransomware operations to expand their affiliate base and market presence.

Qilin is written in Rust and Go, enabling cross-platform attacks against both Windows and Linux environments. Qilin’s modular design allows attackers to customize payloads, set encryption methods, and configure ransom notes. The ransomware has a professionalized infrastructure, including a data leak site where stolen information is published if victims refuse to pay.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Qilin Malware Victimology

Qilin targets a diverse range of organizations across multiple sectors, with a particular focus on high-value targets that are likely to pay substantial ransoms. In June 2025, the United States remained the primary target of ransomware attacks, recording 235 victims, far surpassing other nations. Canada (24), the United Kingdom (24), Germany (15), and Israel (13) also experienced notable activity.

The threat actors behind Qilin demonstrate a clear preference for:

  • Healthcare Organizations: Hospitals and medical facilities are frequent targets due to their critical nature and limited tolerance for downtime
  • Financial Services: Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications.
  • Manufacturing and Industrial Facilities: Critical infrastructure targets that cannot afford extended operational disruptions
  • Educational Institutions: Universities and school districts with valuable research data and personal information
  • Government Agencies: Local and regional government entities with sensitive citizen data
  • Professional Services: Law firms, consulting companies, and other service providers handling confidential client information

The targeting strategy appears to prioritize organizations in developed economies where cyber insurance coverage is common and ransom payment capabilities are higher. The geographical distribution reflects this focus, with North America and Europe representing the majority of victims.

Qilin Ransomware Attack Chain and Technical Details

One of Qilin’s features is the requirement to input a unique password, passed as a command-line argument when launching the executable file, which enhances its protection against analysis.

The community of about half a million users of ANY.RUN’s Interactive Sandbox has submitted and analyzed a number of Qilin’s samples featuring this password input. Let’s view an analysis with a correctly entered password.
View Qilin detonated in the Sandbox

Qilin analysis in Interactive Sandbox Qilin sample analysis in the Interactive Sandbox

Qilin employs commands to manipulate symbolic links in Windows, altering the system's behavior regarding the handling of symbolic links. The commands used are:

fsutil behavior set SymlinkEvaluation R2R:1
fsutil behavior set SymlinkEvaluation R2L:1

Qilin link commands Qilin link commands in the process tree in the Interactive Sandbox

To conceal the traces of its activity, Qilin clears system logs, making it difficult to detect and analyze the attack, using a PowerShell script:

Qilin PowerShell script Qilin log wiping PowerShell script

Subsequently, the malware destroys Volume Shadow Copies (VSS) to prevent data recovery without paying the ransom. To do this, the ransomware executes a sequence of commands that manipulate the Volume Shadow Copy Service and deletes all existing snapshots. The commands used are:

net start vss wmic service where name='vss' call ChangeStartMode Manual vssadmin.exe delete shadows /all /quiet net stop vss wmic service where name='vss' call ChangeStartMode Disabled

Qilin also uses commands to prevent failures in cluster services and to propagate through a domain environment via Active Directory (AD). These commands include:

Stop-Cluster -Force

Import-Module ActiveDirectory ; Get-ADComputer -Filter * | Select-Object -ExpandProperty DNSHostName

ServerManagerCmd.exe -i RSAT-AD-PowerShell ; Install-WindowsFeature RSAT-AD-PowerShell ; Add-WindowsCapability -Online -Name 'RSAT.ActiveDirectory.DS-LDS.Tools~0.0.1.0'

Qilin encrypts files, appending an extension composed of a unique set of random characters for each attack. This extension is also included in the name of the ransom note file left in the infected directories.

How Qilin Ransomware Generally Functions

Qilin operates through a sophisticated technical architecture designed for maximum effectiveness and stealth. Adversaries operating the Qilin ransomware adopt a multi-pronged strategy to breach target networks, relying on both misconfigurations and software vulnerabilities.

Common Entry Points:

  • Vulnerability exploitation
  • Exploitation of unpatched VPN appliances and firewalls
  • Compromise of Remote Desktop Protocol (RDP) services
  • Phishing campaigns targeting employee credentials
  • Supply chain compromises through trusted vendor access
  • Exploitation of public-facing web applications
  • Abuse of legitimate remote access tools

Lateral Movement Techniques:

  • Once inside a network, Qilin employs various techniques to spread:
  • Credential dumping from compromised systems
  • Pass-the-hash and pass-the-ticket attacks
  • Exploitation of Windows vulnerabilities for privilege escalation
  • Living-off-the-land techniques using legitimate system tools
  • Network scanning to identify additional targets
  • Abuse of administrative tools like PowerShell and WMI

Network Persistence:

  • Creation of backdoor accounts and hidden administrative access
  • Installation of remote access tools for persistent connectivity
  • Modification of security policies to maintain access
  • Deployment of additional payloads for redundant access

Advanced Evasion Techniques:

Further, Qilin uses various code obfuscation methods, such as renaming functions, altering control flows, and encrypting strings, to complicate reverse engineering efforts. This also makes Qilin difficult to detect with IOCs located further along the killchain.

Anti-Analysis Mechanisms:

To further hinder analysis, Qilin integrates anti-analysis mechanisms designed to identify and disable debugging and sandbox environments. It actively scans for virtual machines and common sandbox artifacts to evade dynamic analysis, preventing security researchers from closely examining its behavior.

Encryption Implementation:

The ransomware implements robust encryption algorithms with the following characteristics:

  • Uses industry-standard AES-256 encryption for file encryption
  • Employs RSA public-key cryptography for key protection
  • Generates unique encryption keys for each infected system
  • Implements secure key management to prevent unauthorized decryption

Communication Infrastructure:

  • Utilizes Tor networks for command and control communications
  • Implements secure communication protocols to protect operator anonymity
  • Maintains redundant infrastructure to ensure operational continuity
  • Uses cryptocurrency payment systems for ransom collection

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

What Qilin Malware Can Do to an Endpoint Device

When Qilin successfully infiltrates a device, it implements a multi-stage attack process designed to maximize damage while evading detection:

Initial Compromise and Persistence:

  • Establishes persistence mechanisms through registry modifications and scheduled tasks
  • Creates backup access points to maintain access even if primary entry vectors are discovered
  • Disables Windows Defender and other security solutions through privilege escalation

System Manipulation:

Using renamed binaries like upd.exe (a spoof of legitimate AV updaters), Qilin ransomware disables EDR, clears logs, and bypasses detection. The malware might even exploit outdated Carbon Black Cloud sensors to remain hidden.

Credential Harvesting:

Once elevated, Qilin dumps LSASS memory and extracts credentials to facilitate lateral movement across the network. This process allows the ransomware to escalate privileges and access additional systems.

Data Encryption Process:

  • Encrypts files using strong cryptographic algorithms, typically AES-256 with RSA key protection
  • Targets specific file types while avoiding system files necessary for basic OS functionality
  • Appends custom file extensions to encrypted files
  • Drops ransom notes in multiple locations across the infected system
  • Modifies desktop wallpaper to display ransom information

System Degradation:

  • Disables system recovery features including Windows System Restore
  • Deletes shadow copies and backup files to prevent easy recovery
  • Clears event logs to hinder forensic analysis
  • May corrupt or delete system files to increase recovery complexity.

Notable Qilin Attacks

The scope of Qilin's operations has grown dramatically. investigated network artifacts related to Qilin and identified three probable cases of the ransomware across the Darktrace customer base between June 2022 and May 2024. However, by 2025, the frequency had increased exponentially, with the group claiming dozens of victims monthly.

A Qilin Ransomware Attack hit a U.S. financial advisory firm on July 1, 2025. The attackers allegedly exfiltrated approximately 340 GB of sensitive data, potentially including confidential financial records, client information, and internal communications. This incident underscores the persistent threat Qilin poses to financial services organizations.

The Qilin ransomware group launched attacks exploiting Fortinet vulnerabilities CVE-2024-21762 and CVE-2024-55591 between May and June 2025. These attacks demonstrated Qilin's ability to target critical infrastructure through systematic exploitation of network security appliances.

Multiple healthcare organizations have fallen victim to Qilin attacks, resulting in cancelled surgeries, delayed medical procedures, and compromised patient care. These attacks highlight the life-threatening potential of ransomware when targeting critical infrastructure.

Several universities and school districts have been targeted, resulting in exposure of student records, research data, and administrative systems. These attacks often occur during critical periods such as registration or examination periods to maximize pressure for ransom payment.

Gathering Threat Intelligence on Qilin Ransomware

Effectively countering such complex threats as Qilin is impossible without access to a large volume of detailed up-to-date threat Intelligence. It fuels:

  • Proactive detection based on studying the malware's behavior before it attacks corporate systems.
  • Creating High-Quality Signatures and Correlation Rules: Understanding specific commands, scripts, and sequences of actions enables the configuration of security systems (SIEM, EDR) for precise attack detection.
  • Investigating Incidents: TI data helps analysts quickly understand the scope and methods of an attack, identify affected systems, and take appropriate response actions.

Indicators of Compromise (IOCs) include:

  • Presence of unusual Rust/Go executables.
  • Suspicious processes terminating backups or security tools.
  • Encrypted files with unique extensions set by affiliates.
  • Outbound connections to Tor-based C2 servers.
  • Ransom notes dropped across multiple directories.

Behavioral detection (via EDR/XDR) is critical: look for privilege escalation, mass file encryption, and registry tampering.

Start using Threat Intelligence Lookup for free: collect IOCs, browse sandbox detonations.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deeper into contextual data on Qilin. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"qilin"

Qilin samples found via Threat Intelligence Lookup Qilin sample analyses found via Threat Intelligence Lookup

To find Qilin samples with the above-mentioned password submitting, use an additional search parameter:

threatName:"Qilin" and commandLine:"password"

Qilin samples with password found via Threat Intelligence Lookup Qilin samples with password analyzed in the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Qilin is now one of the most prominent ransomware threats globally. Its rapid rise, adoption by advanced threat actors, and the growing number of victims in late 2024 and early 2025 point to sustained activity well into the years ahead. The threat is likely to persist and potentially intensify, making preparation and prevention more critical than ever.

The ransomware family represents a significant evolution in cybercriminal sophistication, combining advanced technical capabilities with effective business operations to create a formidable threat.

Although Qilin follows a typical ransomware attack chain, its success lies in the effectiveness of its evasion strategies, allowing it to execute attacks with minimal detection until the final encryption phase.

The fight against Qilin ransomware is not just a technical challenge but also a strategic business imperative. Organizations that invest in comprehensive cybersecurity programs, maintain current threat intelligence, and prepare for incident response will be better positioned to resist this sophisticated threat and protect their critical assets and operations.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for quick detection and response.

HAVE A LOOK AT

Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More