Microsoft links Scattered Spider hackers to Qilin ransomware attacks

Share:

Microsoft says the Scattered Spider cybercrime gang has added Qilin ransomware to its arsenal and is now using it in attacks.

“In the second quarter of 2024, financially motivated threat actor Octo Tempest, our most closely tracked ransomware threat actor, added RansomHub and Qilin to its ransomware payloads in campaigns,” Microsoft said Monday.

After surfacing in early 2022, this threat group (also tracked as Octo Tempest, UNC3944, and 0ktapus) achieved notoriety following their 0ktapus campaign that targeted over 130 high-profile organizations, including Microsoft, Binance, CoinBase, T-Mobile, Verizon Wireless, AT&T, Slack, Twitter, Epic Games, Riot Games, and Best Buy.

The English-speaking gang has also encrypted MGM Resorts’ systems after joining BlackCat/ALPHV ransomware as an affiliate in mid-2023 and was linked by Symantec to the RansomHub ransomware-as-a-service.

In November, the FBI and CISA issued an advisory highlighting Scattered Spider’s tactics, techniques, and procedures (TTPs). These include impersonating IT employees to trick customer service staff into providing them with credentials or gaining persistence on targets’ networks using remote access tools.

Other tactics they’re known to use for initial network access include phishing, MFA bombing (aka MFA fatigue), and SIM swapping.

​The Qilin ransomware operation that Scattered Spider just joined surfaced in August 2022 under the “Agenda” name but was rebranded as Qilin just one month later.

Over the last two years, the Qilin gang has claimed over 130 companies on its dark web leak site; however, their operators weren’t active until attacks picked up towards the end of 2023.

Since December 2023, Qilin has also been developing one of the most advanced and customizable Linux encryptors to target VMware ESXi virtual machines, which enterprise organizations favor for their light resource needs.

Like many other ransomware groups targeting businesses, Qilin operators infiltrate a company’s networks and extract data as they move through the victim’s systems.

After obtaining admin credentials and collecting all sensitive data, they deploy the ransomware payloads to encrypt all network devices and leverage the stolen data to carry out double-extortion attacks.

So far, BleepingComputer has seen Qilin ransom demands ranging from as low as $25,000 to millions of dollars, depending on the victim’s size.

Last month, the CEO of the UK’s National Cyber Security Centre (NCSC) linked Qilin to a ransomware attack that hit pathology services provider Synnovis in early June and impacted several major NHS hospitals in London, forcing them to cancel hundreds of operations and appointments.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:55 pm, May 9, 2025
weather icon 13°C
L: 12° | H: 14°
clear sky
Humidity: 56 %
Pressure: 1021 mb
Wind: 12 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 10%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:17 am
Sunset: 8:35 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
12° | 14°°C 0 mm 0% 8 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 20°°C 0 mm 0% 11 mph 77 % 1021 mb 0 mm/h
Sun May 11 10:00 pm
weather icon
11° | 22°°C 0.66 mm 66% 11 mph 80 % 1015 mb 0 mm/h
Mon May 12 10:00 pm
weather icon
13° | 21°°C 0.38 mm 38% 14 mph 91 % 1014 mb 0 mm/h
Tue May 13 10:00 pm
weather icon
13° | 20°°C 1 mm 100% 10 mph 83 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
12° | 13°°C 0 mm 0% 8 mph 56 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 12°°C 0 mm 0% 6 mph 61 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 11°°C 0 mm 0% 4 mph 77 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 76 % 1020 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 9 mph 40 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 30 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 11 mph 34 % 1017 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 41 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,822.46
0.93%
Ethereum(ETH)
€2,073.81
7.64%
Tether(USDT)
€0.89
0.00%
XRP(XRP)
€2.09
2.37%
Solana(SOL)
€153.35
6.32%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.182341
5.62%
Shiba Inu(SHIB)
€0.000013
5.25%
Pepe(PEPE)
€0.000011
9.66%
Peanut the Squirrel(PNUT)
€0.320741
68.14%
Scroll to Top