Qilin Ransomware Using Ghost Bulletproof Hosting to Attack Organizations Worldwide
The Qilin ransomware group has emerged as a significant threat in the cybersecurity landscape, utilizing advanced bulletproof hosting infrastructure to execute attacks across various sectors.
The Qilin ransomware group has emerged as a significant threat in the cybersecurity landscape, utilizing advanced bulletproof hosting infrastructure to execute attacks across various sectors.
Operating under a Ransomware-as-a-Service (RaaS) model, Qilin initially appeared in mid-2022 under the name "Agenda." The group has been known to target healthcare organizations, government entities, critical infrastructure operators, and asset management firms worldwide.
Qilin's ransomware variants are developed in both Golang and Rust, enabling cross-platform attacks. Initial access is typically gained through spear phishing campaigns, followed by the use of Remote Monitoring and Management (RMM) tools and other penetration tools to establish persistence in compromised networks.
The group employs double extortion techniques, encrypting data and exfiltrating sensitive information to pressure victims into ransom payments. Affiliates use user-friendly panels to configure attacks and manage victims, while a Data Leak Site on the Tor network is used to publish stolen data.
Qilin's ransomware variants are developed in both Golang and Rust, enabling cross-platform attacks.
Qilin's operations are supported by an underground bulletproof hosting network, with origins in Russian-speaking cybercriminal forums and Hong Kong. These hosting services operate in pro-secrecy jurisdictions, structured across anonymous shell companies, enabling operations with minimal oversight.
The group's infrastructure involves partnerships with providers like Cat Technologies Co. Limited in Hong Kong, sharing connections with other entities such as Starcrecium Limited and Chang Way Technologies Co. Limited. These providers are linked to Russia-based Hostway.ru, complicating law enforcement tracking efforts.
Bulletproof hosting services range from $95 to $500 and offer mass scanning capabilities with bandwidth up to 10 Gbps. Providers like BEARHOST Servers have advertised directly on Qilin's platform, offering services without Know Your Customer (KYC) protocols or due diligence checks.
Corporate records indicate interconnectedness among multiple legal entities, complicating accountability. The U.S. Treasury Department has sanctioned entities providing these services to cybercriminals, affecting operations like BEARHOST, which transitioned to private mode and later executed an exit scam, leaving customers without access or refunds.
Based on reporting by Cyber Security News.
