Qilin
13
MENTIONS
5
EPISODES
5
PODCASTS
Search complete. 13 mentions across 5 episodes found for "Qilin".
Sep 23, 2026
The hunters go after the bureau.
D
9:35Dave BittnerHOST
NCC noted that some cybercriminals are increasingly skipping encryption and moving directly to data theft and extortion.
D
9:43Dave BittnerHOST
Among identified groups, Qilin led with one hundred and sixty-four attributed incidents, followed by The Gentlemen with one hundred and sixteen, and Clop with eighty-nine.
D
9:54Dave BittnerHOST
NCC says August marked the second consecutive month of record ransomware activity for the year and recommends organizations maintain response playbooks and conduct tabletop exercises to prepare for attacks.
D
10:10Dave BittnerHOST
Microsoft has disrupted Evil Tokens, an AI-enabled cybercrime platform linked to more than twelve thousand compromised inboxes across over ten thousand organizations since launching in February.
Tech: Mathspace edutech breach, Storm ransomware explosion
T
5:56Tony GrossoGUEST
Um, okay.
T
5:56Tony GrossoGUEST
So, so Storm ransomware, um, they're a Russian-speaking crime group called Qilin.
T
6:04Tony GrossoGUEST
Um, why this is, uh, of particular interest is that they are targeting ...
T
6:09Tony GrossoGUEST
It's a new ransomware operator that's targeting Australia and New Zealand, right? So anyone who, uh, listens to these segments regularly will probably think, "I'm sure he's done this story before." Um, and I have.
Mikrotik and Cisco Active Exploits - The 443 Podcast - Episode 387
C
19:24Corey NachreinerHOST
... you know, a victim of this kind of thing.
M
19:27Marc LaliberteHOST
The, uh, back to the story for Cisco's FM- FMC software, the third threat actor was a Qilin ransomware operator, where they were using the static credentials to gain access and then ultimately elevate privileges.
M
19:41Marc LaliberteHOST
They then used that as kind of a bastion to do network reconnaissance of the networks that the, um, firewall management server had access to.
M
19:49Marc LaliberteHOST
They staged a reverse socks proxy and tunnel for persistent access, and then ultimately deployed antivirus killers and then the Qilin ransomware family to affected systems.
C
20:00Corey NachreinerHOST
I'm glad you pronounced that.
C
20:01Corey NachreinerHOST
I still would... don't default to the right.
C
20:04Corey NachreinerHOST
Qilin with a Q.
M
20:06Marc LaliberteHOST
It's, I think it's an...
Assorted Calibers Podcast Ep 405: We Now Return To Regular Podcasting
E
12:50Erin PauletteHOST
But it was a standalone system that wasn't connected to any other systems, including case management, laboratory systems, or eForms, and it was quickly shut down when the breach was discovered, although they're not saying how long it was between infection and discovery.
E
13:07Erin PauletteHOST
Now, I've, I've never heard of this Qilin.
W
13:11Weird BeardHOST
Yeah.
E
13:12Erin PauletteHOST
Q-I-L-I-N.
Srsly Risky Biz: China's botnets are worth disrupting
J
10:37James WilsonHOST
And now all we knew at that time was that this was a ransomware attack.
J
10:41James WilsonHOST
It was, um, uh, supposedly the Qilin, the Russian speaking group was, was, uh, potentially behind this.
J
10:47James WilsonHOST
And all we knew was it was an isolated system that contained information about targets that the ATF, uh, the, of course, the Alcohol, Tobacco, and Firearms Bureau was, uh, investigating.
J
10:59James WilsonHOST
What do we know now, Tom?
T
11:26Tom UrenGUEST
And so this is like a, that's a pretty sensitive system.
T
11:29Tom UrenGUEST
It tells people who they're targeting, what they might know about them in terms of phone numbers, IP addresses, that sort of thing.
T
11:38Tom UrenGUEST
So subsequent to that, uh, information coming out, the director saying it was a CLEA system, Qilin, uh, briefly published, [chuckles] is the, the word that was on Twitter, a dump of 6.3 gigabytes.
T
11:56Tom UrenGUEST
And I suppose in terms of an extortion campaign, it's the, "Here's the proof of what we've got." And it included, uh, mobile phone forensics, case files with details of targets.