Neuer Qilin-Ransomware-Verschlüsseler bietet stärkere Verschlüsselung und Umgehung

Teilen:

A new Rust-based version of the Qilin (Agenda) ransomware strain, dubbed ‘Qilin.B,’ has been spotted in attacks, featuring stronger encryption, better evasion from security tools, and the ability to disrupt data recovery mechanisms.

Qilin.B was spotted by security researchers at Halcyon, who warned about the threat and shared indicators of compromise to help with early detection.

Qilin updates its encryptor

Starting with the new encryption scheme, Qilin.B users AES-256-CTR with AESNI capabilities for CPUs that support it, speeding up the encryption.

However, the new strain retains ChaCha20 for weaker or older systems that don’t have the appropriate hardware for AESNI, ensuring robust encryption in any case.

Qilin.B also incorporates RSA-4096 with OAEP padding for encryption key protection, making decryption nearly impossible without the private key or captured seed values.

Upon execution, the new Qilin malware adds an autorun key in the Windows Registry for persistence and terminates the following processes to free up critical data for encryption and disable security tools.

  • Veeam (backup and recovery)
  • Windows Volume Shadow Copy Service (system backup and recovery)
  • SQL database services (enterprise data management)
  • Sophos (security and antivirus software)
  • Acronis Agent (backup and recovery service)
  • SAP (enterprise resource planning)

Existing volume shadow copies are wiped to prevent easy system restoration, and Windows Event Logs are cleared to hinder forensic analysis. The ransomware binary is also deleted after the encryption process has been completed.

Qilin.B targets both local directories and network folders and generates ransom notes for each directory processed, including the victim ID in the title.

Qilin ransom note
Qilin ransom note
Quelle: BleepingComputer

For maximum reach, it modified the Registry with a separate entry to enable sharing of network drives between elevated and non-elevated processes.

Although the above are not ground-breaking features in the ransomware space, they can have a severe and far-reaching impact when they’re added to a family used by notorious threat groups in highly effective attacks.

Last August, Sophos revealed that Qilin deploys a custom info-stealer in attacks to collect credentials stored in the Google Chrome browser and extend their attacks to entire networks or re-introduce itself on breached networks even after cleanups.

Previously, Qilin was used in highly damaging attacks against major London hospitals, Court Services Victoria in Australia, and automotive giant Yanfeng.

The group also uses a Linux variant focused on VMware ESXi attacks, but the variant Halcyon spotted concerns Windows systems.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:12 pm, Juni 22, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 49 %
Druck: 1013 mb
Wind: 13 mph W
Windböe: 24 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 17 mph 47 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 12 mph 32 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,150.11
-1.14%
Ethereum(ETH)
€1,972.17
-7.00%
Fesseln(USDT)
€0.87
0.02%
XRP(XRP)
€1.75
-5.55%
Solana(SOL)
€115.59
-6.47%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.134930
-4.86%
Shiba Inu(SHIB)
€0.000010
-5.20%
Pepe(PEPE)
€0.000008
-9.13%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen