Skip to main content

Search complete. 13 mentions across 5 episodes found for "Qilin".

Sep 23, 2026

Dave BittnerHOST
9:35
NCC noted that some cybercriminals are increasingly skipping encryption and moving directly to data theft and extortion.
Dave BittnerHOST
9:43
Among identified groups, Qilin led with one hundred and sixty-four attributed incidents, followed by The Gentlemen with one hundred and sixteen, and Clop with eighty-nine.
Dave BittnerHOST
9:54
NCC says August marked the second consecutive month of record ransomware activity for the year and recommends organizations maintain response playbooks and conduct tabletop exercises to prepare for attacks.
Dave BittnerHOST
10:10
Microsoft has disrupted Evil Tokens, an AI-enabled cybercrime platform linked to more than twelve thousand compromised inboxes across over ten thousand organizations since launching in February.
Tony GrossoGUEST
5:56
Um, okay.
Tony GrossoGUEST
5:56
So, so Storm ransomware, um, they're a Russian-speaking crime group called Qilin.
Tony GrossoGUEST
6:04
Um, why this is, uh, of particular interest is that they are targeting ...
Tony GrossoGUEST
6:09
It's a new ransomware operator that's targeting Australia and New Zealand, right? So anyone who, uh, listens to these segments regularly will probably think, "I'm sure he's done this story before." Um, and I have.
Corey NachreinerHOST
19:24
... you know, a victim of this kind of thing.
Marc LaliberteHOST
19:27
The, uh, back to the story for Cisco's FM- FMC software, the third threat actor was a Qilin ransomware operator, where they were using the static credentials to gain access and then ultimately elevate privileges.
Marc LaliberteHOST
19:41
They then used that as kind of a bastion to do network reconnaissance of the networks that the, um, firewall management server had access to.
Marc LaliberteHOST
19:49
They staged a reverse socks proxy and tunnel for persistent access, and then ultimately deployed antivirus killers and then the Qilin ransomware family to affected systems.
Corey NachreinerHOST
20:00
I'm glad you pronounced that.
Corey NachreinerHOST
20:01
I still would... don't default to the right.
Corey NachreinerHOST
20:04
Qilin with a Q.
Marc LaliberteHOST
20:06
It's, I think it's an...
Erin PauletteHOST
12:50
But it was a standalone system that wasn't connected to any other systems, including case management, laboratory systems, or eForms, and it was quickly shut down when the breach was discovered, although they're not saying how long it was between infection and discovery.
Erin PauletteHOST
13:07
Now, I've, I've never heard of this Qilin.
Weird BeardHOST
13:11
Yeah.
Erin PauletteHOST
13:12
Q-I-L-I-N.
James WilsonHOST
10:37
And now all we knew at that time was that this was a ransomware attack.
James WilsonHOST
10:41
It was, um, uh, supposedly the Qilin, the Russian speaking group was, was, uh, potentially behind this.
James WilsonHOST
10:47
And all we knew was it was an isolated system that contained information about targets that the ATF, uh, the, of course, the Alcohol, Tobacco, and Firearms Bureau was, uh, investigating.
James WilsonHOST
10:59
What do we know now, Tom?
Tom UrenGUEST
11:26
And so this is like a, that's a pretty sensitive system.
Tom UrenGUEST
11:29
It tells people who they're targeting, what they might know about them in terms of phone numbers, IP addresses, that sort of thing.
Tom UrenGUEST
11:38
So subsequent to that, uh, information coming out, the director saying it was a CLEA system, Qilin, uh, briefly published, [chuckles] is the, the word that was on Twitter, a dump of 6.3 gigabytes.
Tom UrenGUEST
11:56
And I suppose in terms of an extortion campaign, it's the, "Here's the proof of what we've got." And it included, uh, mobile phone forensics, case files with details of targets.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.