August 25, 2026
The Ransomware Group Currently Active Against Pakistan’s Financial Sector, Healthcare System, and…
Week 4 — Intelligence Production | August 25, 2026 2,207 victims. One confirmed patient death. Five Pakistani organizations hit in 12…

By H3NRY B41T
14 min read
Week 4 — Intelligence Production | August 25, 2026 2,207 victims. One confirmed patient death. Five Pakistani organizations hit in 12 months. This is what the investigation found.
Why Qilin, Why Now
On August 23, 2026, while working through the last week of my 30-day CTI program, I opened ransomware.live to find a target for a live intelligence investigation. Qilin had published five Italian companies in a single batch that morning. Pakistan's Crown Group was posted eleven days earlier with an unresolved publication threat. Dr Akbar Niazi Teaching Hospital in Islamabad appeared on the same day.
This was not a historical exercise. This was active.
The Group
Qilin — also tracked as Agenda and GOLD FEATHER — is a Ransomware-as-a-Service operation active since July 2022. The core group builds and maintains the ransomware platform. Affiliates conduct the attacks and keep 80–85% of ransom payments. The core group takes the rest.
Two things define Qilin above other ransomware groups.
First, they do not avoid healthcare. Most groups claim hospitals are off-limits. Qilin has no such policy.
Second, they consistently avoid targeting organizations in Russia and the former Soviet states — the clearest public indicator that their operators are based in that region.
As of August 23, 2026: 2,207 confirmed victims across 101 countries. Named by Sophos CTU as the most prevalent ransomware operation between January 2024 and December 2025.
The Timeline
July 2022 — First samples detected under the name Agenda. Written in Go.
September 2022 — Rebrands to Qilin. First victim posted October 8, 2022.
February 9, 2024 — CVE-2024–21762 published. Fortinet FortiOS out-of-bounds write. CVSS 9.6 Critical. Unauthenticated remote code execution against SSL-VPN devices. Qilin affiliates adopt it as primary initial access within weeks.
June 3, 2024 — Synnovis attack. London NHS blood services encrypted. 11,000 appointments cancelled. $50 million ransom demanded. 400GB patient data stolen and published when payment was refused.
July 2024 — Sophos X-Ops documents a new Qilin technique: Chrome credential harvesting via Group Policy Object across entire Active Directory domains.
Mid-2024 — Qilin.B variant released. Rewritten in Rust. Self-deletes after execution. Clears Windows Event logs. Deletes Volume Shadow Copies. Significantly harder to reverse engineer than the Go version.
November 5, 2025 — Habib Bank AG Zurich posted to Qilin leak site. 2.5TB stolen.
October 11, 2025 — Greenstar Social Marketing Pakistan attacked.
December 2025 — Sophos CTU confirms the complete attack chain: ClickFix → NetSupport RAT → StealC → IAB → Fortinet VPN → ransomware.
June 25, 2025 — BBC confirms one patient death linked to the Synnovis attack. First confirmed ransomware-linked patient death in UK history.
January 2026 — RansomHub disrupted by law enforcement. Qilin absorbs displaced affiliates. Attack volume surges.
July 22, 2026 — EFU Life Assurance Pakistan posted. SOCRadar stealer-log telemetry shows credentials were harvested July 17–21 — five days before the listing.
August 11, 2026 — Crown Group Pakistan posted. Data publication threat active and unresolved.
August 23, 2026 — Investigation date. Five Italian companies batch-published. Dr Akbar Niazi Teaching Hospital Islamabad posted by Kazu. 2,207 total Qilin victims confirmed.
The Synnovis Attack — When Ransomware Kills
On June 3, 2024, Qilin encrypted Synnovis — the pathology lab processing blood tests for King's College Hospital and Guy's and St Thomas' NHS Foundation Trust in London.
The immediate impact: over 11,000 appointments and procedures cancelled. GP practices across South-East London unable to order blood tests. Blood transfusion matching disrupted across multiple hospitals.
On June 25, 2025 — one year later — King's College Hospital confirmed one patient had died unexpectedly, with a long wait for a blood test result due to the cyber attack identified as a contributing factor.
Qilin's response when contacted by the BBC: they were "sorry" but "not to blame." They claimed the attack was political revenge for UK government actions in an undisclosed conflict.
Synnovis did not pay. Qilin published 400GB of patient data on June 20, 2024 — seventeen days after the attack. Services were not fully restored until December 2024.
The Chrome Credential Harvesting Technique
In July 2024, Sophos X-Ops documented something new during a Qilin incident response engagement.
After gaining access to a domain controller via a VPN portal with no MFA — 18 days after initial compromise — the attacker modified the default domain Group Policy to deploy two files:
IPScanner.ps1 — a 19-line PowerShell script that harvested all credentials stored in Google Chrome browsers, writing results to a SQLite database file named LD and a text file named temp.log in the SYSVOL share.
logon.bat — a batch script that executed IPScanner.ps1 on every user login across the entire domain.
The GPO remained active for over three days. Every user login during that window became a credential theft event. The average user has approximately 87 work-related passwords saved in Chrome. Every one of them — plus personal banking, personal email, every external site — exfiltrated.
After collection, the attacker deleted all files, cleared Windows Event logs, then deployed ransomware via a GPO-triggered scheduled task.
The blast radius extends far beyond the victim organization. Employees whose Chrome passwords were stolen become vectors for attacks on completely unrelated systems — personal banks, other employers, any site where they reuse passwords.
The Attack Chain
Confirmed by Sophos CTU December 2025. This is the documented Qilin kill chain from first contact to encryption:
- ClickFix Lure Victim visits a compromised legitimate website. A fake human verification page instructs them to press a key combination. This downloads and executes NetSupport Manager — a legitimate remote access tool used as a RAT.
2. NetSupport RAT Connects to attacker C2 server (documented case: ports 3389, 443, 5986 exposed). Downloads StealC V2 payload.
3. StealC V2 Credential Theft Infostealer harvests VPN credentials, email credentials, browser passwords. Exfiltrated to attacker.
4. Initial Access Broker Sale Stolen credentials sold on underground marketplaces. Qilin affiliate purchases validated corporate VPN access. Time between StealC infection and Qilin deployment in documented case: approximately one month.
5. VPN Access — No MFA Affiliate authenticates to Fortinet VPN using purchased credentials. Dwell time: 18 days.
6. Domain Controller Compromise Lateral movement using compromised Active Directory credentials.
7. Chrome GPO Harvesting IPScanner.ps1 deployed via Group Policy. Domain-wide credential theft for 3+ days.
8. Data Exfiltration MEGA or EasyUpload.io for bulk data. FTP to documented exfiltration servers (176.113.115.209, 176.113.115.97) as alternative channel.
9. Evidence Destruction All harvested files deleted. Windows Event logs cleared. Volume Shadow Copies deleted.
10. Ransomware Deployment Qilin.B via GPO-triggered scheduled task. Self-deletes after execution. Ransom note dropped in every directory.
Pakistan: Five Victims, One Pipeline
Qilin is the #1 ransomware group targeting Pakistan, tied with Clop at 17.6% of all confirmed Pakistani victims. 22 total ransomware attacks against Pakistani organizations confirmed across 10 different groups in the tracked period.
Habib Bank AG Zurich — November 5, 2025
One of Pakistan's most internationally connected banks, with representative offices and remittance services serving the Pakistani diaspora globally.
Qilin claimed 2.5TB stolen — nearly 2 million files including customer passport numbers, account balances, transaction histories, KYC documentation, internal source code, and employee records.
The theft of source code is the most technically serious element. It reveals system architecture and authentication mechanisms — information usable for follow-on attacks or sale to other threat actors.
The bank confirmed unauthorized access but stated services remained operational.
Greenstar Social Marketing — October 11, 2025
Greenstar runs maternal health, contraception distribution, and health systems strengthening programs across Pakistan. Its beneficiaries are some of Pakistan's most vulnerable populations.
Hudson Rock infostealer telemetry: 1 compromised employee credential, 26 third-party credential exposures, Microsoft 365 as the detected cloud service — likely the initial access surface.
This is not a high-revenue target. The attack demonstrates opportunistic affiliate behavior — access was available, so ransomware was deployed regardless of the victim's ability to pay.
EFU Life Assurance — July 22, 2026
One of Pakistan's largest insurance companies. The most technically precise intelligence finding in this investigation.
SOCRadar stealer-log telemetry returned approximately 25 records for the efulife.com domain, including two corporate webmail credentials. The credential harvest window: July 17–21, 2026 — five days before the Qilin listing.
The pipeline, visible in real time:
July 17-21 → Infostealer harvests EFU corporate credentials
→ Credentials sold on underground marketplace
July 22 → Qilin affiliate acquires and validates access
→ EFU Life Assurance appears on Qilin leak siteJuly 17-21 → Infostealer harvests EFU corporate credentials
→ Credentials sold on underground marketplace
July 22 → Qilin affiliate acquires and validates access
→ EFU Life Assurance appears on Qilin leak siteThis is the Sophos-documented ClickFix → StealC → IAB → Qilin chain operating against a Pakistani target. The five-day window between harvest and listing represents the detection opportunity that most organizations miss.
Crown Group — August 11, 2026
Business services provider. Posted August 11, 2026. Threat: "Full leak will be published soon."
As of August 23, 2026: unresolved. Live incident.
Dr Akbar Niazi Teaching Hospital — August 23, 2026
500-bed tertiary care teaching hospital in Islamabad. Posted by Kazu — not Qilin — on the same day as this investigation. Part of the same Pakistan ransomware surge.
The Broader Picture
Beyond Qilin, Pakistan is being simultaneously targeted by multiple groups:
- Clop — Treet Corp, Treet Group, PAFL (manufacturing)
- WorldLeaks — Descon Engineering (1.6TB fully leaked), Orient Petroleum
- Beast — Punjab Forensic Science Agency (law enforcement forensic lab)
- DragonForce — Medipak Limited (pharmaceutical)
- The Gentlemen — Beaconhouse schools, SHAJARPAK Securities
- DireWolf — Hyundai Nishat Motor
The Punjab Forensic Science Agency breach deserves specific attention. This is Pakistan's primary forensic evidence laboratory used by courts and law enforcement across Punjab. A breach of case data could compromise active criminal investigations.
The Malware
Sample analyzed: SHA-256 d4eb523c293db7ca230c687924b96a1b8cde6b8c2f10d971dec138447a8eb64d
- VirusTotal detection: 57/69
- Compiled: February 15, 2025
- Family confirmed: Qilin/Agenda by Joe Sandbox (88/100), NeikiAnalytics (100/100), Kaspersky, and two THOR YARA rules authored by Florian Roth
- Language: Rust (Qilin.B variant)
- Behavioral tags: detect-debug-environment, overlay
The THOR YARA matches — MAL_RANSOM_Qilin_Rust_Loader_Feb24_1 — specifically call this the same loader used in a documented PSI cyberattack, confirming the sample is part of the active Qilin.B campaign infrastructure.
Encryption: ChaCha20 / AES-256-CTR with RSA-4096 key protection. Each victim receives a unique file extension. Operator-selectable encryption modes: normal, skip, fast, percent.
Exfiltration servers:
- 176.113.115.209–5/91 VirusTotal detections. Linked to Qilin in two analyst investigation graphs. Passive DNS shows nexo-branded domains in October 2024.
- 176.113.115.97 — Zero AbuseIPDB reports. Zero Shodan results. Ghost server, presenting nothing to passive scanners.
The exfiltration infrastructure is deliberately kept cleaner than the ransomware samples. Keeping these servers off blocklists ensures victim data transfers complete without network controls triggering.
Priority Intelligence Requirements
Five questions that should drive any CTI program monitoring this threat:
PIR-1: Which ransomware groups are currently conducting operations against Pakistani financial services organizations and what initial access vectors are they using?
PIR-2: Are Pakistani organizational credentials currently available on underground marketplaces or infostealer log dumps?
PIR-3: What Fortinet VPN or Microsoft 365 vulnerabilities are being actively exploited by ransomware affiliates against Pakistani organizations?
PIR-4: Which Pakistani victims have data currently staged for publication, and what is the timeline?
PIR-5: Is there evidence of Qilin affiliates purchasing Pakistani organizational access from initial access brokers on criminal forums?
Hunt Hypotheses
Hunt 1: Compromised VPN Credentials — Active Dwell
Hypothesis: A Qilin affiliate is currently inside our network using purchased VPN credentials, in the 18-day pre-ransomware dwell phase.
Data sources: VPN authentication logs, Event ID 4624, geographic IP lookup
Logic: Query 30 days of VPN authentications. Flag any account where source IP geolocation does not match the account's last 5 logins AND authentication occurred outside normal hours AND no MFA record exists. Cross-reference source IPs against Qilin IOC list.
Hit definition: All three conditions met simultaneously. Treat as confirmed investigation.
On hit: Do not terminate the session. Scope first. Identify all touched systems. Escalate to IR. Coordinate simultaneous containment.
Hunt 2: Chrome GPO Harvesting In Progress
Hypothesis: IPScanner.ps1 has been deployed via Group Policy and Chrome credentials are being harvested across our domain right now.
Data sources: Event ID 5136 (GPO modification), Sysmon Event ID 11 (file creation), SYSVOL share access logs
Logic:
- Search for GPO modifications outside approved change management windows in last 14 days
- Search for files named "LD" (no extension) or "temp.log" created in SYSVOL directories
- Search for PowerShell processes referencing both SYSVOL paths and Chrome Login Data paths
Hit definition: Any single condition warrants investigation. All three confirmed = active Qilin Chrome harvesting operation.
On hit: Immediately remove the malicious GPO entries. Assume all users who logged in since GPO modification have been compromised. Force domain-wide password reset. Notify all users to change external site passwords. Escalate to IR.
Hunt 3: Post-Compromise Reconnaissance Cluster
Hypothesis: A Qilin affiliate is in the post-access discovery phase — conducting Active Directory reconnaissance before deploying ransomware.
Data sources: Event ID 4688 (process creation with command line)
Logic: Search for any user account executing four or more of these commands within 60 minutes: net user /domain, net group "Domain Admins", nltest /domain_trusts, whoami /all, ipconfig /all, systeminfo, wmic computersystem get, query user.
Hit definition: Standard user account executing this cluster. Administrator account executing this cluster from a workstation.
On hit: Do not alert the account owner or reset credentials until IR is ready for simultaneous containment. Premature action triggers ransomware deployment.
Detection Rules
Sigma Rule 1: Chrome GPO Credential Harvesting
title: Qilin Chrome Credential Harvesting via Group Policy
id: 7f3a2b1c-d4e5-6789-abcd-ef0123456789
status: experimental
description: >
Detects file creation in SYSVOL consistent with Qilin's IPScanner.ps1
Chrome harvesting technique documented by Sophos X-Ops July 2024.
references:
- https://news.sophos.com/en-us/2024/10/31/qilin-ransomware-caught-stealing-credentials-stored-in-google-chrome/
author: H3NRY B41T
date: 2026/08/23
logsource:
category: file_event
product: windows
detection:
selection_sysvol_db:
TargetFilename|contains: '\SYSVOL\'
TargetFilename|endswith: '\LD'
selection_sysvol_log:
TargetFilename|contains: '\SYSVOL\'
TargetFilename|endswith: '\temp.log'
selection_powershell_chrome:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains|all:
- 'Login Data'
- 'SYSVOL'
condition: 1 of selection_*
falsepositives:
- Legitimate administrative scripts writing to SYSVOL (extremely rare)
level: critical
tags:
- attack.credential_access
- attack.t1555.003
- attack.t1484.001title: Qilin Chrome Credential Harvesting via Group Policy
id: 7f3a2b1c-d4e5-6789-abcd-ef0123456789
status: experimental
description: >
Detects file creation in SYSVOL consistent with Qilin's IPScanner.ps1
Chrome harvesting technique documented by Sophos X-Ops July 2024.
references:
- https://news.sophos.com/en-us/2024/10/31/qilin-ransomware-caught-stealing-credentials-stored-in-google-chrome/
author: H3NRY B41T
date: 2026/08/23
logsource:
category: file_event
product: windows
detection:
selection_sysvol_db:
TargetFilename|contains: '\SYSVOL\'
TargetFilename|endswith: '\LD'
selection_sysvol_log:
TargetFilename|contains: '\SYSVOL\'
TargetFilename|endswith: '\temp.log'
selection_powershell_chrome:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains|all:
- 'Login Data'
- 'SYSVOL'
condition: 1 of selection_*
falsepositives:
- Legitimate administrative scripts writing to SYSVOL (extremely rare)
level: critical
tags:
- attack.credential_access
- attack.t1555.003
- attack.t1484.001Sigma Rule 2: VSS Deletion — Pre-Ransomware
title: Volume Shadow Copy Deletion — Ransomware Pre-Deployment
id: 9c3d8f2a-b5e1-4567-cdef-012345678901
status: stable
description: Detects VSS deletion via multiple methods. Universal Qilin pre-encryption step.
author: H3NRY B41T
date: 2026/08/23
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains|all:
- 'delete'
- 'shadows'
selection_wmic:
Image|endswith: '\wmic.exe'
CommandLine|contains|all:
- 'shadowcopy'
- 'delete'
selection_powershell:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'Win32_ShadowCopy'
- 'DeleteObject'
selection_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains|all:
- 'recoveryenabled'
- 'No'
condition: 1 of selection_*
falsepositives:
- Legitimate backup software (document and whitelist)
level: critical
tags:
- attack.impact
- attack.t1490title: Volume Shadow Copy Deletion — Ransomware Pre-Deployment
id: 9c3d8f2a-b5e1-4567-cdef-012345678901
status: stable
description: Detects VSS deletion via multiple methods. Universal Qilin pre-encryption step.
author: H3NRY B41T
date: 2026/08/23
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains|all:
- 'delete'
- 'shadows'
selection_wmic:
Image|endswith: '\wmic.exe'
CommandLine|contains|all:
- 'shadowcopy'
- 'delete'
selection_powershell:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'Win32_ShadowCopy'
- 'DeleteObject'
selection_bcdedit:
Image|endswith: '\bcdedit.exe'
CommandLine|contains|all:
- 'recoveryenabled'
- 'No'
condition: 1 of selection_*
falsepositives:
- Legitimate backup software (document and whitelist)
level: critical
tags:
- attack.impact
- attack.t1490Sigma Rule 3: AD Reconnaissance Cluster
title: Post-Compromise Active Directory Reconnaissance Cluster
id: 4e7b9f1d-c2a3-5678-efab-234567890123
status: experimental
description: >
Detects behavioral cluster of AD reconnaissance commands consistent
with Qilin post-compromise discovery. Dwell time is 18 days.
Detection here allows containment before ransomware deployment.
author: H3NRY B41T
date: 2026/08/23
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\net.exe'
- '\net1.exe'
- '\nltest.exe'
- '\whoami.exe'
- '\systeminfo.exe'
CommandLine|contains:
- '/domain'
- 'domain_trusts'
- '/all'
- 'Domain Admins'
filter_admin_tools:
ParentImage|contains:
- '\ServerManager'
condition: selection and not filter_admin_tools
falsepositives:
- IT administrators running legitimate inventory scripts
level: high
tags:
- attack.discovery
- attack.t1069.002
- attack.t1087.002title: Post-Compromise Active Directory Reconnaissance Cluster
id: 4e7b9f1d-c2a3-5678-efab-234567890123
status: experimental
description: >
Detects behavioral cluster of AD reconnaissance commands consistent
with Qilin post-compromise discovery. Dwell time is 18 days.
Detection here allows containment before ransomware deployment.
author: H3NRY B41T
date: 2026/08/23
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\net.exe'
- '\net1.exe'
- '\nltest.exe'
- '\whoami.exe'
- '\systeminfo.exe'
CommandLine|contains:
- '/domain'
- 'domain_trusts'
- '/all'
- 'Domain Admins'
filter_admin_tools:
ParentImage|contains:
- '\ServerManager'
condition: selection and not filter_admin_tools
falsepositives:
- IT administrators running legitimate inventory scripts
level: high
tags:
- attack.discovery
- attack.t1069.002
- attack.t1087.002YARA Rule: Qilin Ransom Note
rule Qilin_Agenda_Ransom_Note {
meta:
description = "Detects Qilin/Agenda ransom notes"
author = "H3NRY B41T"
date = "2026-08-23"
reference = "https://ransomware.live/group/qilin"
tlp = "WHITE"
strings:
$brand_qilin = "-- Qilin" ascii
$brand_agenda = "-- Agenda" ascii
$section_warning = "-- Warning" ascii
$section_recovery = "-- Recovery" ascii
$section_credentials = "-- Credentials" ascii
$threat = "If you refuse to communicate with us" ascii
$tor = "Download tor browser" ascii nocase
$warning = "cipher key / our decrypt software" ascii
$media = "Our group cooperates with the mass media" ascii
$note_filename = "README-RECOVER" ascii
condition:
filesize < 100KB and
($brand_qilin or $brand_agenda) and
$section_warning and
$section_recovery and
$tor and
(2 of ($threat, $warning, $media, $note_filename))
}rule Qilin_Agenda_Ransom_Note {
meta:
description = "Detects Qilin/Agenda ransom notes"
author = "H3NRY B41T"
date = "2026-08-23"
reference = "https://ransomware.live/group/qilin"
tlp = "WHITE"
strings:
$brand_qilin = "-- Qilin" ascii
$brand_agenda = "-- Agenda" ascii
$section_warning = "-- Warning" ascii
$section_recovery = "-- Recovery" ascii
$section_credentials = "-- Credentials" ascii
$threat = "If you refuse to communicate with us" ascii
$tor = "Download tor browser" ascii nocase
$warning = "cipher key / our decrypt software" ascii
$media = "Our group cooperates with the mass media" ascii
$note_filename = "README-RECOVER" ascii
condition:
filesize < 100KB and
($brand_qilin or $brand_agenda) and
$section_warning and
$section_recovery and
$tor and
(2 of ($threat, $warning, $media, $note_filename))
}Intelligence Confidence Assessment
Qilin responsible for five Pakistani victims — HIGH Each entry sourced from ransomware.live, cross-referenced with SOCRadar. Habib Bank confirmed by independent security reporting.
Infostealer pipeline is the dominant initial access for Pakistani victims — MODERATE EFU Life provides direct five-day evidence. Greenstar's Hudson Rock data confirms credential exposure. Sophos CTU confirms the pipeline operationally. Not every victim has confirmed infostealer precursor data.
CVE-2024–21762 is the primary exploitation vector — HIGH Documented in ransomware.live vulnerability matrix, Check Point reporting, and Sophos IR documentation.
Qilin operators are Russian-speaking — MODERATE CIS avoidance policy consistent. Grammar errors in ransom notes consistent with non-native English. No government attribution exists in open-source reporting.
Crown Group data will be published — MODERATE Consistent with Qilin's documented behavior when negotiation fails. Current negotiation status unknown.
Collection Gaps
Gap 1: Current Crown Group negotiation status Cannot be determined from passive OSINT.
Gap 2: Pakistani credentials on underground marketplaces EFU Life proves this intelligence is actionable. But direct access to Russian Market and equivalent platforms requires paid commercial services. This is a critical gap — organizations may have credentials for sale right now without knowing it.
Gap 3: Qilin affiliate targeting methodology Whether Pakistani organizations are deliberately targeted as a campaign or selected opportunistically from IAB listings cannot be determined through passive OSINT.
Gap 4: True scope of victim compromises What was actually exfiltrated from each Pakistani victim beyond what Qilin claims cannot be confirmed without direct access to victim organizations.
IOC Package
## IOC Package
The following indicators of compromise (IOCs) were identified during the analysis:
| Type | Value | Confidence | Source |
| ------ | ------------------------------------------------------------------------------ | ---------- | ----------------------------------------------------- |
| IPv4 | `176.113.115.209` | High | Qilin FTP exfiltration server |
| IPv4 | `176.113.115.97` | High | Qilin FTP exfiltration server — ghost server |
| IPv4 | `188.119.66.189` | High | Qilin infrastructure |
| IPv4 | `31.41.244.100` | High | Qilin infrastructure |
| IPv4 | `85.209.11.49` | High | Qilin infrastructure — active OPSEC |
| SHA256 | `d4eb523c293db7ca230c687924b96a1b8cde6b8c2f10d971dec138447a8eb64d` | High | Qilin.B Rust loader — 57/69 VirusTotal detections |
| MD5 | `08a2405cd32f044a69737e77454ee2da` | High | Qilin.B sample |
| SHA256 | `11fab1676b3c3fd01f4f0ab84eab9bb474a1483d20d2634b35bd637279b029ac` | High | Qilin sample |
| Onion | `ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion` | High | Qilin blog/leak site |
| Onion | `kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion` | High | Qilin secondary blog |
| Onion | `wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion` | High | Qilin negotiation portal |
| Onion | `e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion` | High | Qilin negotiation portal |
| Tox | `7C35408411AEEBD53CDBCEBAB167D7B22F1E66614E89DFCB62EE835416F60E1BCD6995152B68` | High | Qilin contact |
| CVE | `CVE-2024-21762` | Critical | Fortinet FortiOS — CVSS 9.6; primary initial access |
| CVE | `CVE-2024-55591` | High | Fortinet FortiOS authentication bypass |
| CVE | `CVE-2023-27532` | High | Veeam Backup exploitation |
| Tool | `IPScanner.ps1` | High | Chrome credential-harvesting script |
| Tool | `logon.bat` | High | GPO execution batch file |
| Tool | `StealC V2` | High | Infostealer observed in the documented Qilin pipeline |## IOC Package
The following indicators of compromise (IOCs) were identified during the analysis:
| Type | Value | Confidence | Source |
| ------ | ------------------------------------------------------------------------------ | ---------- | ----------------------------------------------------- |
| IPv4 | `176.113.115.209` | High | Qilin FTP exfiltration server |
| IPv4 | `176.113.115.97` | High | Qilin FTP exfiltration server — ghost server |
| IPv4 | `188.119.66.189` | High | Qilin infrastructure |
| IPv4 | `31.41.244.100` | High | Qilin infrastructure |
| IPv4 | `85.209.11.49` | High | Qilin infrastructure — active OPSEC |
| SHA256 | `d4eb523c293db7ca230c687924b96a1b8cde6b8c2f10d971dec138447a8eb64d` | High | Qilin.B Rust loader — 57/69 VirusTotal detections |
| MD5 | `08a2405cd32f044a69737e77454ee2da` | High | Qilin.B sample |
| SHA256 | `11fab1676b3c3fd01f4f0ab84eab9bb474a1483d20d2634b35bd637279b029ac` | High | Qilin sample |
| Onion | `ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion` | High | Qilin blog/leak site |
| Onion | `kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion` | High | Qilin secondary blog |
| Onion | `wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion` | High | Qilin negotiation portal |
| Onion | `e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion` | High | Qilin negotiation portal |
| Tox | `7C35408411AEEBD53CDBCEBAB167D7B22F1E66614E89DFCB62EE835416F60E1BCD6995152B68` | High | Qilin contact |
| CVE | `CVE-2024-21762` | Critical | Fortinet FortiOS — CVSS 9.6; primary initial access |
| CVE | `CVE-2024-55591` | High | Fortinet FortiOS authentication bypass |
| CVE | `CVE-2023-27532` | High | Veeam Backup exploitation |
| Tool | `IPScanner.ps1` | High | Chrome credential-harvesting script |
| Tool | `logon.bat` | High | GPO execution batch file |
| Tool | `StealC V2` | High | Infostealer observed in the documented Qilin pipeline |What This Investigation Found
Qilin is not a future threat to Pakistani organizations. It is a current one.
Five confirmed victims in 12 months. A credential pipeline that gives a five-day detection window before ransomware deployment — a window that goes unused when organizations are not monitoring for it. VPN portals without MFA. Fortinet devices unpatched against a February 2024 vulnerability rated 9.6 out of 10.
The intelligence in this blog gives defenders three things: the specific attack chain to detect, the behavioral indicators to hunt for, and the detection rules to deploy. None of it requires paid tools. All of it is actionable today.
Week 1 taught me to follow a domain. Week 2 taught me to follow infrastructure. Week 3 taught me to follow an actor. Week 4 taught me what all of it is actually for — giving defenders the five-day window they did not know they had.
30 days. Four investigations. All passive OSINT. All free tools.