Microsoft links Scattered Spider hackers to Qilin ransomware attacks

Share:

Microsoft says the Scattered Spider cybercrime gang has added Qilin ransomware to its arsenal and is now using it in attacks.

“In the second quarter of 2024, financially motivated threat actor Octo Tempest, our most closely tracked ransomware threat actor, added RansomHub and Qilin to its ransomware payloads in campaigns,” Microsoft said Monday.

After surfacing in early 2022, this threat group (also tracked as Octo Tempest, UNC3944, and 0ktapus) achieved notoriety following their 0ktapus campaign that targeted over 130 high-profile organizations, including Microsoft, Binance, CoinBase, T-Mobile, Verizon Wireless, AT&T, Slack, Twitter, Epic Games, Riot Games, and Best Buy.

The English-speaking gang has also encrypted MGM Resorts’ systems after joining BlackCat/ALPHV ransomware as an affiliate in mid-2023 and was linked by Symantec to the RansomHub ransomware-as-a-service.

In November, the FBI and CISA issued an advisory highlighting Scattered Spider’s tactics, techniques, and procedures (TTPs). These include impersonating IT employees to trick customer service staff into providing them with credentials or gaining persistence on targets’ networks using remote access tools.

Other tactics they’re known to use for initial network access include phishing, MFA bombing (aka MFA fatigue), and SIM swapping.

​The Qilin ransomware operation that Scattered Spider just joined surfaced in August 2022 under the “Agenda” name but was rebranded as Qilin just one month later.

Over the last two years, the Qilin gang has claimed over 130 companies on its dark web leak site; however, their operators weren’t active until attacks picked up towards the end of 2023.

Since December 2023, Qilin has also been developing one of the most advanced and customizable Linux encryptors to target VMware ESXi virtual machines, which enterprise organizations favor for their light resource needs.

Like many other ransomware groups targeting businesses, Qilin operators infiltrate a company’s networks and extract data as they move through the victim’s systems.

After obtaining admin credentials and collecting all sensitive data, they deploy the ransomware payloads to encrypt all network devices and leverage the stolen data to carry out double-extortion attacks.

So far, BleepingComputer has seen Qilin ransom demands ranging from as low as $25,000 to millions of dollars, depending on the victim’s size.

Last month, the CEO of the UK’s National Cyber Security Centre (NCSC) linked Qilin to a ransomware attack that hit pathology services provider Synnovis in early June and impacted several major NHS hospitals in London, forcing them to cancel hundreds of operations and appointments.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:49 am, May 9, 2025
weather icon 10°C
L: 8° | H: 11°
overcast clouds
Humidity: 82 %
Pressure: 1021 mb
Wind: 6 mph NE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:17 am
Sunset: 8:35 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
8° | 11°°C 0 mm 0% 12 mph 82 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 20°°C 0 mm 0% 12 mph 86 % 1021 mb 0 mm/h
Sun May 11 10:00 pm
weather icon
11° | 23°°C 0.94 mm 94% 12 mph 86 % 1015 mb 0 mm/h
Mon May 12 10:00 pm
weather icon
12° | 21°°C 0.97 mm 97% 11 mph 95 % 1016 mb 0 mm/h
Tue May 13 10:00 pm
weather icon
13° | 21°°C 0.46 mm 46% 11 mph 77 % 1022 mb 0 mm/h
Today 10:00 am
weather icon
10° | 13°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
12° | 16°°C 0 mm 0% 12 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
15° | 17°°C 0 mm 0% 11 mph 49 % 1020 mb 0 mm/h
Today 7:00 pm
weather icon
15° | 15°°C 0 mm 0% 9 mph 40 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
12° | 12°°C 0 mm 0% 8 mph 63 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 6 mph 74 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
9° | 9°°C 0 mm 0% 4 mph 86 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 79 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,406.70
4.54%
Ethereum(ETH)
€2,051.89
18.89%
Tether(USDT)
€0.89
-0.01%
XRP(XRP)
€2.08
6.73%
Solana(SOL)
€146.94
8.85%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.183516
13.13%
Shiba Inu(SHIB)
€0.000013
10.30%
Pepe(PEPE)
€0.000011
31.07%
Peanut the Squirrel(PNUT)
€0.260461
73.56%
Scroll to Top