Microsoft links Scattered Spider hackers to Qilin ransomware attacks

Share:

Microsoft says the Scattered Spider cybercrime gang has added Qilin ransomware to its arsenal and is now using it in attacks.

“In the second quarter of 2024, financially motivated threat actor Octo Tempest, our most closely tracked ransomware threat actor, added RansomHub and Qilin to its ransomware payloads in campaigns,” Microsoft said Monday.

After surfacing in early 2022, this threat group (also tracked as Octo Tempest, UNC3944, and 0ktapus) achieved notoriety following their 0ktapus campaign that targeted over 130 high-profile organizations, including Microsoft, Binance, CoinBase, T-Mobile, Verizon Wireless, AT&T, Slack, Twitter, Epic Games, Riot Games, and Best Buy.

The English-speaking gang has also encrypted MGM Resorts’ systems after joining BlackCat/ALPHV ransomware as an affiliate in mid-2023 and was linked by Symantec to the RansomHub ransomware-as-a-service.

In November, the FBI and CISA issued an advisory highlighting Scattered Spider’s tactics, techniques, and procedures (TTPs). These include impersonating IT employees to trick customer service staff into providing them with credentials or gaining persistence on targets’ networks using remote access tools.

Other tactics they’re known to use for initial network access include phishing, MFA bombing (aka MFA fatigue), and SIM swapping.

​The Qilin ransomware operation that Scattered Spider just joined surfaced in August 2022 under the “Agenda” name but was rebranded as Qilin just one month later.

Over the last two years, the Qilin gang has claimed over 130 companies on its dark web leak site; however, their operators weren’t active until attacks picked up towards the end of 2023.

Since December 2023, Qilin has also been developing one of the most advanced and customizable Linux encryptors to target VMware ESXi virtual machines, which enterprise organizations favor for their light resource needs.

Like many other ransomware groups targeting businesses, Qilin operators infiltrate a company’s networks and extract data as they move through the victim’s systems.

After obtaining admin credentials and collecting all sensitive data, they deploy the ransomware payloads to encrypt all network devices and leverage the stolen data to carry out double-extortion attacks.

So far, BleepingComputer has seen Qilin ransom demands ranging from as low as $25,000 to millions of dollars, depending on the victim’s size.

Last month, the CEO of the UK’s National Cyber Security Centre (NCSC) linked Qilin to a ransomware attack that hit pathology services provider Synnovis in early June and impacted several major NHS hospitals in London, forcing them to cancel hundreds of operations and appointments.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:09 am, Jul 11, 2025
weather icon 18°C
L: 16° | H: 19°
scattered clouds
Humidity: 80 %
Pressure: 1021 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 45%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 19°°C 0 mm 0% 8 mph 76 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 7:00 am
weather icon
18° | 19°°C 0 mm 0% 2 mph 76 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 2 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 32 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Tomorrow 4:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 66 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,711.92
4.88%
Ethereum(ETH)
€2,534.30
6.46%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€2.21
6.74%
Solana(SOL)
€140.98
4.20%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.169861
9.70%
Shiba Inu(SHIB)
€0.000012
9.28%
Pepe(PEPE)
€0.000011
15.02%
Peanut the Squirrel(PNUT)
€0.248685
22.27%
Scroll to Top