Threat Advisory

Qilin Ransomware Targets Global Healthcare Sector to Encrypting Data

Threat: Ransomware
Targeted Region: Australia, Canada, U.K. & U.S.
Threat Actor Region: Russia
Targeted Sector: Government & Defense, Technology & IT, Healthcare, Finance & Banking, Retail & E-Commerce, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Qilin is a ransomware-as-a-service (RaaS) offering that has been targeting healthcare organizations and various other industries worldwide. Originating from Russia, the group was observed recruiting affiliates. Qilin ransomware has variants written in Golang and Rust and gains initial access through spear phishing, leveraging Remote Monitoring and Management (RMM) tools, and other common methods. The group practices double extortion, demanding ransom payments to prevent data from being leaked.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Qilin is a ransomware-as-a-service (RaaS) offering that has been targeting healthcare organizations and various other industries worldwide. Originating from Russia, the group was observed recruiting affiliates. Qilin ransomware has variants written in Golang and Rust and gains initial access through spear phishing, leveraging Remote Monitoring and Management (RMM) tools, and other common methods. The group practices double extortion, demanding ransom payments to prevent data from being leaked.[emaillocker id="1283"]

Qilin ransomware, initially developed in Golang, now has variants written in Rust. It primarily targets Windows systems, but the Linux version was focusing on VMware ESXi servers. Ransomware gains initial access through spear phishing, exposed applications, and interfaces such as Citrix and RDP. It uses Remote Monitoring and Management (RMM) tools and Cobalt Strike for deployment and propagates via PsExec and SecureShell. The malware employs multiple encryption algorithms, including ChaCha20, AES-256, and RSA4096, and incorporates various obfuscation techniques. It also customizes filename extensions of encrypted files and terminates specific processes and services for optimal functionality.

Qilin ransomware continues to pose a significant threat to various industries worldwide, particularly the healthcare sector. With over 60 attacks claimed, the group's activities have steadily increased. Victims have been reported in countries including Australia, Canada, the United Kingdom, and the United States. Despite payment demands, there is no guarantee of data recovery, emphasizing the need for robust cybersecurity measures and awareness to mitigate the risks posed by this evolving ransomware operation.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1190 Exploit Public-Facing Application
 Execution T1569 System Services
T1053 Scheduled Task/Job
Persistence T1037 Boot or Logon Initialization Scripts
 Privilege Escalation T1068 Exploitation for Privilege Escalation
T1548 Abuse Elevation Control Mechanism
 Defense Evasion T1078 Valid Accounts
T1055 Process Injection
T1014 Rootkit
T1211 Exploitation for Defense Evasion
T1480 Execution Guardrails
T1497 Virtualization/Sandbox Evasion
T1027 Obfuscated Files or Information
Credential Access  T1003 OS Credential Dumping
 Discovery  T1082 System Information Discovery
T1010 Application Window Discovery
T1046 Network Service Discovery
T1018 Remote System Discovery
Lateral Movement T1021 Remote Services
T1570 Lateral Tool Transfer
Collection  T1005 Data from Local System
Command and Control  T1001 Data Obfuscation
Exfiltration T1011 Exfiltration Over Other Network Medium
 Impact T1486 Data Encrypted for Impact
T1485 Data Destruction
T1490 Inhibit System Recovery
T1561 Disk Wipe

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/hc3-unveils-qilin-ransomware/

[/emaillocker]
crossmenu