Malware
Qilin
Qilin ransomware, initially observed in July 2022 under the name “Agenda,” operates on a Ransomware-as-a-Service (RaaS) model. This model allows core developers to provide their malicious software and infrastructure to affiliates in exchange for a percentage of the profits generated from attacks. The name “Qilin” references a Chinese mythological creature symbolizing power and prosperity, a fitting metaphor for the group’s perceived influence and financial objectives. Despite the Chinese name, the group is linked to Russian-speaking cybercriminals, often recruiting affiliates on Russian-language forums and notably excluding Commonwealth of Independent States (CIS) countries from its targets.
Indicators of Compromise 100
Domain 1710[.]rwlp[.]be Domain authorized-logins[.]net Domain b6w9m2z5x8q1v3k[.]top Domain carrolc[.]com Domain crazyeltonproxy[.]top Domain datalayerservice[.]com Domain devminelimited[.]com Domain doctecsolutions[.]com Domain microsoft[.]desereyunton[.]workers[.]dev Domain pool[.]hashvault[.]pro Domain rebronzeal[.]com Domain strapness[.]com Domain summonhood[.]com Domain technodatabase[.]net Filename !light.bat Filename /tmp/.dbus-cache Filename /tmp/.dbus-cache/gmon Filename /tmp/amd64 Filename /tmp/x86_64 Filename AAct.exe Filename C:\PerfLogs\ Filename HRSword.exe Filename HRSword.lnk Filename SECOH-QAD.exe Filename TeamViewer_Host_Setup – <encryptor_2>.exe Filename VID001.exe Filename WCInstaller_NonAdmin.exe Filename accumulatally.ps1 Filename cmd.jar Filename content.js Filename d4aa3e7010220ad1b458fac17039c274_62_Exe.exe Filename d4aa3e7010220ad1b458fac17039c274_63_Exe.exe Filename dark.sys Filename earthquakeist.ps1 Filename encryptor_1.exe Filename encryptor_2.exe Filename evasion.node Filename home.jsp Filename license.tmp Filename main.exe Filename pars.vbs Filename result.txt Filename sample.exe GitHub Repo AdaptixC2 GitHub Repo TalosIntel/IOCs GitHub Repo impacket/impacket GitHub User impacket MD5 207d9d891ac756b2bfad88aba5682c65 MD5 2915b3f8b703eb744fc54c81f4a9c67f MD5 38de5b216c33833af710e88f7f64fc98 MD5 41444d7018601b599beac0c60ed1bf83 MD5 7bdbd180c081fa63ca94f9c22c457376 MD5 9a47c4d379998ade2f8f99e23a630c06 MD5 aac3165ece2959f39ff98334618d10d9 SHA-256 164cad33a0b076a6d01263e159ad06d2e7b1e9e1ace43294c252b11699022485 SHA-256 1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984 SHA-256 232b5115f4b78fe01c6497b1039b85ee57f6a58abd095dc80ea4d3c5e6cef6d6 SHA-256 24d71cb6cf6d34871031564c3f104195b812f8e72ceffb1f0ce1936998531e6f SHA-256 34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc SHA-256 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 SHA-256 3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be SHA-256 59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712 SHA-256 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 SHA-256 8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235 SHA-256 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 SHA-256 a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 SHA-256 afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c SHA-256 b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d SHA-256 c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 SHA-256 c854382d457eddbae9887350f9f19a2bc35c02968900b8f534503d0dcbd824a5 SHA-256 cd211247d1c1c1ca4d77418fea60efafd0736017ef35c9191aed85c684adc153 SHA-256 d965de63dbd27abb00efeb9bea029cd38952dc5c268b61a522b2358d8452e43a SHA-256 db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e SHA-256 db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5 SHA-256 e237801a9ef693d0d4c7d148965bb50c90946b43b8b9e00aa5e39fe5393a26e9 SHA-256 e901df53873d5379ad9399c63d3e014c7be188a7599b32e5b36b1de1cf7d5fba SHA-256 f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e SHA-256 fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a SHA-256 fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f IP 104[.]218[.]165[.]253 IP 139[.]28[.]37[.]250 IP 142[.]93[.]242[.]144 IP 144[.]31[.]53[.]78 IP 151[.]241[.]99[.]207 IP 151[.]241[.]99[.]233 IP 158[.]62[.]198[.]182 IP 185[.]62[.]1[.]8 IP 185[.]84[.]98[.]85 IP 192[.]142[.]10[.]99 IP 198[.]13[.]159[.]44 IP 199[.]91[.]221[.]42 IP 208[.]123[.]119[.]215 IP 43[.]204[.]2[.]142 IP 45[.]158[.]196[.]23 IP 89[.]34[.]96[.]56 IP 91[.]214[.]78[.]118 IP 94[.]26[.]106[.]29 Package AnyDesk
MITRE ATT&CK TTPs 82
T1003 T1012 T1016 T1018 T1021 T1021.001 T1021.002 T1027 T1033 T1040 T1046 T1047 T1048 T1053 T1055 T1057 T1059 T1059.001 T1070.001 T1070.004 T1071 T1071.001 T1075 T1078 T1078.004 T1081 T1082 T1083 T1086 T1087 T1087.002 T1089 T1090 T1095 T1098 T1105 T1110 T1110.003 T1112 T1120 T1129 T1133 T1176 T1189 T1190 T1202 T1203 T1210 T1211 T1212 T1218 T1222 T1222.001 T1482 T1484.001 T1485 T1486 T1489 T1490 T1495 T1534 T1537 T1542.001 T1543.003 T1547.001 T1548.002 T1550 T1552.001 T1558 T1562.001 T1566 T1566.002 T1569 T1570 T1573 T1574.002 T1588 T1588.001 T1589 T1595 T1599 T1650
OS Credential Dumping
Credential Access
Query Registry
Discovery
System Network Configuration Discovery
Discovery
Remote System Discovery
Discovery
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Obfuscated Files or Information
Defense Evasion
System Owner/User Discovery
Discovery
Network Sniffing
Credential Access
Network Service Discovery
Discovery
Windows Management Instrumentation
Execution
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task/Job
Execution
Process Injection
Defense Evasion
Process Discovery
Discovery
Command and Scripting Interpreter
Execution
PowerShell
Execution
Clear Windows Event Logs
Defense Evasion
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
T1075
Valid Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
T1081
System Information Discovery
Discovery
File and Directory Discovery
Discovery
T1086
Account Discovery
Discovery
Domain Account
Discovery
T1089
Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Password Spraying
Credential Access
Modify Registry
Defense Evasion
Peripheral Device Discovery
Discovery
Shared Modules
Execution
External Remote Services
Persistence
Browser Extensions
Persistence
Drive-by Compromise
Initial Access
Exploit Public-Facing Application
Initial Access
Indirect Command Execution
Defense Evasion
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
Exploitation for Credential Access
Credential Access
System Binary Proxy Execution
Defense Evasion
File and Directory Permissions Modification
Defense Evasion
Windows File and Directory Permissions Modification
Defense Evasion
Domain Trust Discovery
Discovery
Group Policy Modification
Defense Evasion
Data Destruction
Impact
Data Encrypted for Impact
Impact
Service Stop
Impact
Inhibit System Recovery
Impact
Firmware Corruption
Impact
Internal Spearphishing
Lateral Movement
Transfer Data to Cloud Account
Exfiltration
System Firmware
Persistence
Windows Service
Persistence
Registry Run Keys / Startup Folder
Persistence
Bypass User Account Control
Privilege Escalation
Use Alternate Authentication Material
Defense Evasion
Credentials In Files
Credential Access
Steal or Forge Kerberos Tickets
Credential Access
Disable or Modify Tools
Defense Evasion
Phishing
Initial Access
Spearphishing Link
Initial Access
System Services
Execution
Lateral Tool Transfer
Lateral Movement
Encrypted Channel
Command And Control
DLL Side-Loading
Persistence
Obtain Capabilities
Resource Development
Malware
Resource Development
Gather Victim Identity Information
Reconnaissance
Active Scanning
Reconnaissance
Network Boundary Bridging
Defense Evasion
Acquire Access
Resource Development
Source Articles
Should you care about an “AI slowdown?”
Cisco Talos reports on a rising ransomware threat landscape in Japan, with a nearly 5% increase in incidents in the first half of 2026. Two prominent ransomware actors, 'The Gentlemen' and 'Qilin', are driving this surge. Qilin leverages generative AI to accelerate attacks by creating destructive scripts, while The Gentlemen uses legitimate red-teaming tools like AdaptixC2 to blend in and evade detection. Both groups target small- and medium-sized enterprises using double-extortion tactics, emphasizing the need for improved credential management, MFA enforcement, and updated defenses using available Snort rules.
talos ·2w ago
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
In the first half of 2026, ransomware incidents in Japan increased slightly by 4.7%, with The Gentlemen emerging as the most active group, responsible for 14 incidents. The group operates via a Ransomware-as-a-Service (RaaS) model and uses a double-extortion tactic, leveraging infrastructure including AdaptixC2 for command-and-control. Evidence from Russian-language artifacts in scripts and bash history suggests Russian-speaking actors are involved. Qilin, the second most active group, showed signs of using generative AI in developing attack scripts, with code exhibiting structured, LLM-like patterns in tools for deploying ransomware and wiping backups.
talos ·2w ago
Node.js: Old Technique Makes a Comeback
Multiple threat actors have revived the abuse of Node.js to evade detection by executing malicious JavaScript payloads through the legitimate, signed node.exe runtime. The attacks, observed since February 2026, targeted government departments, technology companies, and hotels. In one campaign, attackers used a ClickFix-style lure to deploy PowerShell scripts, established persistence, and leveraged Node.js to connect to Ethereum blockchain gateways (EtherHiding) for command retrieval. A related intrusion involved the deployment of a Rust-based backdoor, C2Looper, linked to ransomware operations. The same actors used shared infrastructure, including the C2 domain datalayerservice[.]com and IP 45.158.196[.]23:8888, across multiple victims.
security-com ·4w ago
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Multiple threat actor clusters have exploited two critical vulnerabilities in Cisco's Secure Firewall Management Center (FMC) to gain unauthorized access, steal credentials, and deploy ransomware. CVE-2026-20079, a critical authentication bypass flaw (CVSS 10.0), allowed unauthenticated remote attackers to execute scripts and gain root access. CVE-2026-20316, a lower-severity flaw, enabled access via a low-privilege account and was used in conjunction with other vulnerabilities for privilege escalation. Three distinct post-compromise activity clusters were identified: UAT-12197 deployed JSP web shells and JAR-based command executors; UAT-11823 delivered Netcat reverse shells and a Cyclops Blink variant; and UAT-11988, a ransomware operation, used living-off-the-land techniques to deploy Qilin ransomware.
hacker-news ·3w ago
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos identified three threat clusters exploiting two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079 (authentication bypass, CVSS 10.0) and CVE-2026-20316 (static credentials, CVSS 5.3). UAT-11988, linked to Qilin ransomware affiliates, used static credentials to deploy ransomware after reconnaissance and lateral movement. UAT-11823, attributed to the Sandworm APT group, exploited both flaws to deploy a Cyclops Blink variant for persistent access and credential theft. UAT-12197 deployed a JSP web shell and malicious JAR file to steal credentials. Cisco confirmed exploitation of both vulnerabilities in active attacks.
bleeping-computer ·3w ago
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software: CVE-2026-20079, a critical authentication bypass flaw, and CVE-2026-20316, which allows login via a low-privileged account. Three distinct threat clusters have been identified: UAT-12197 deployed a JSP web shell and a JAR-based command executor; UAT-11823, linked to Sandworm, used CVE-2026-20079 and CVE-2026-20316 to deploy Cyclops Blink malware via a Netcat reverse shell; and UAT-11988, a Qilin ransomware operator, leveraged static credentials to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Customers are urged to apply available patches immediately.
talos ·3w ago
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are exploiting these vulnerabilities to deploy reverse shells, execute arbitrary code, steal credentials, and deploy cryptocurrency miners. Exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall devices has been confirmed, while CVE-2026-9586 and CVE-2026-82329 are being used to gain administrative access and conduct post-exploitation activities. Microsoft and Wiz report active exploitation of CVE-2026-42271 and CVE-2026-48710 in LiteLLM deployments, with attackers achieving remote code execution and stealing API keys, and CVE-2026-49869 in Kestra being used to establish reverse shells and deploy miners.
hacker-news ·4w ago
Inside 90 days of attacks on AI infrastructure
Wiz Threat Research observed 90 days of sustained attacks against AI infrastructure through honeypots deployed across services like LiteLLM, Flowise, and LangChain. Attackers exploited vulnerabilities in MCP servers, including authentication bypass and command injection (CVE-2026-59822, CVE-2026-42271), to achieve remote code execution and deploy cryptominers. A second pattern involved blind prompt injection against AI agent frameworks, where attackers used out-of-band DNS callbacks to confirm execution and later fetch payloads from Pastebin. Post-exploitation activity was tailored to AI environments, including in-memory extraction of LiteLLM master keys, model enumeration, and use of environment-specific camouflage to hide malicious binaries.
wiz
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Gunra ransomware, a Conti-derived operation, has been actively targeting critical infrastructure sectors globally, including healthcare, financial services, and government facilities. The group exploits known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) devices to gain initial access, then uses Impacket tools for lateral movement and credential dumping. Gunra employs a double extortion model, exfiltrating data before encryption, and has listed 51 victims on its leak site since April 2025, primarily in South Korea, Brazil, and Europe. The group has ties to affiliate programs, uses WhatsApp for negotiations, and has demonstrated advanced capabilities such as MFA bypass and session hijacking via SSL-VPN manipulation.
hacker-news ·1mo ago
IT threat evolution in Q2 2026. Non-mobile statistics
In Q2 2026, multiple ransomware groups remained active, with Qilin emerging as the most prolific based on victims listed on data leak sites. Microsoft disrupted a malware-signing-as-a-service operation run by the threat actor Fox Tempest, which was used by several ransomware groups including Rhysida, Akira, and Qilin. CISA added a Windows local privilege escalation vulnerability (CVE-2026-33825, BlueHammer) to its KEV catalog due to active exploitation in ransomware attacks. Check Point attributed zero-day exploitation of a critical vulnerability in its Remote Access VPN (CVE-2026-50751) to the Qilin ransomware group. Additionally, the PayoutsKing group was observed using QEMU to deploy hidden Alpine Linux-based virtual machines as a stealthy backdoor technique.
securelist ·1mo ago