Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Qilin Ransomware Activity Surges as Attacks Target Small Businesses
News

Qilin Ransomware Activity Surges as Attacks Target Small Businesses

Team-CWDBy Team-CWDNovember 11, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A rise in ransomware incidents linked to the Qilin ransomware group, one of the longest-running ransomware-as-a-service (RaaS) operations, has been observed by cybersecurity researchers.

According to S-RM’s latest intelligence, Qilin continues to exploit weaknesses such as unpatched VPN appliances, lack of multi-factor authentication (MFA) and exposed management interfaces to gain initial access to corporate networks.

In an advisory published on Monday, the firm noted that while major breaches, such as the 2024 Synnovis attack on UK healthcare systems, drew widespread attention, most of Qilin’s victims are small-to-medium-sized businesses in the construction, healthcare and financial sectors.

Growing Collaboration Among Cybercrime Groups

Although Qilin has been active for several years, it has largely avoided widespread publicity.

S-RM has now observed that affiliates of the Scattered Spider group are deploying Qilin’s RaaS platform, suggesting deeper collaboration between prominent cybercrime organizations.

Key findings from S-RM’s investigation show that Qilin has operated as a RaaS group since 2023, leasing its tools and infrastructure to affiliates.

The study also showed that initial access is typically gained through unpatched VPNs or single-factor remote access tools.

Additionally, S-RM noted that in 2025, 88% of observed Qilin cases involved both data theft and file encryption, with victims’ data published on dark-web leak sites if no ransom was paid.

Qilin had also begun experimenting with new extortion channels, including Telegram and public sites such as WikiLeaksV2.

Read more on ransomware-as-a-service trends: Ransomware Group Uses AI Chatbot to Intensify Pressure on Victims

A Tech Business, Not Just Hackers

“Qilin is part of a new generation of ransomware groups that operate more like tech businesses than hackers,” said Ted Cowell, head of cybersecurity UK at S-RM.

“Their affiliates rent the tools, share the profits and constantly test new ways to break into networks.”

Cowell added that Qilin’s quiet operations make it particularly dangerous.

“It doesn’t always grab headlines, but it’s increasingly being used by other threat groups, including Scattered Spider […]. That makes attribution harder and defense even more complex,” he explained.

S-RM also emphasized that many breaches still originate from basic security gaps.

To mitigate risks, the firm urges all organizations to:

  • Regularly patch and update VPNs and remote access devices

  • Apply MFA to all accounts

  • Limit or remove exposed management interfaces

  • Segment networks to isolate critical systems

  • Monitor proactively for lateral movement or signs of intrusion

S-RM’s findings highlight the growing professionalism of ransomware networks and the continued need for strong cyber-hygiene across all sectors.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
Next Article Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data
Team-CWD
  • Website

Related Posts

News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

What to consider before asking an AI chatbot for health advice

May 27, 2026

In memoriam: David Harley

November 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.