Qilin Ransomware Leverages Ghost Bulletproof Hosting for Global Attacks
## Qilin Ransomware Exploits Bulletproof Hosting
Qilin Ransomware Exploits Bulletproof Hosting
Qilin ransomware, a ransomware-as-a-service (RaaS) operation, has intensified its global extortion efforts by utilizing bulletproof hosting (BPH) providers. These hosting services allow Qilin's operators to host malware and data leak sites with minimal risk of law enforcement intervention.
In September 2025, Qilin targeted Asahi Group Holdings, disrupting operations for nearly two weeks. This incident highlights the real-world impact of employing such hosting frameworks.
Since its emergence in mid-2022 under the name "Agenda," Qilin has developed into a sophisticated RaaS platform. Affiliates use a web panel for attack configuration, victim management, and ransom negotiations. The ransomware, written in Golang and Rust, includes spear-phishing toolkits, remote monitoring, and double-extortion capabilities.
Affiliates receive 80–85% of ransom payments, while operators take a 15–20% share. Qilin's resilience is supported by bulletproof hosting providers, offering anonymity and resistance to regulatory actions.
These hosting services allow Qilin's operators to host malware and data leak sites with minimal risk of law enforcement intervention.
On September 29, 2025, Qilin executed a ransomware attack on Asahi Group Holdings, disrupting digital order processing and causing nationwide product shortages. The attack led to the exfiltration of 27 GB of data and posed significant financial risks to the company.
Qilin demanded $10 million USD for the stolen data, bypassing intermediaries to increase pressure. This attack resembles previous high-impact incidents targeting manufacturing and critical infrastructure sectors.
Throughout October 2025, Qilin announced new victims in Europe, North America, Africa, and Asia. The collaboration between Qilin and bulletproof hosting operators presents a significant challenge to cybersecurity defenses.
Recent targets include Spain's Tax Administration Agency, U.S. municipalities, healthcare providers, and African insurance technology firms. Qilin's recruitment of international affiliates suggests evolving strategies and collaborations.
Addressing these threats will require coordinated international law enforcement efforts and regulatory actions against the companies supporting BPH services. Without such measures, Qilin is likely to continue leveraging these platforms for high-impact campaigns.
Based on reporting by GBHackers.
