Feeds.Trendmicro
Qilin Ransomware Group Uses Linux Binaries to Target Windows Systems
First seen 2 Nov 2025, 16:14 UTC
•



+1
•21.6
Export
Article Content
Browse articles
The Qilin ransomware group, previously known as Agenda, has been executing attacks on Windows hosts using Linux-based binaries, affecting over 700 victims since January 2025. This cross-platform execution leverages Windows Subsystem for Linux (WSL) and legitimate remote management tools, allowing the group to evade traditional Windows-centric security measures. The group has maintained a high level of activity, publishing more than 40 victim listings per month on its leak site.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.