ThreatCluster

Qilin Ransomware Uses WSL to Run Linux Encryptors on Windows

First seen 2 Dec 2025, 18:33 UTC TechradarMsn 100% similarity 19

Article Content

Browse articles
ThreatCluster

Qilin ransomware has been identified using Windows Subsystem for Linux (WSL) to execute Linux encryptors on Windows systems, allowing attackers to bypass traditional Windows defenses. The malware operates by executing ELF binaries, enhancing its stealth and effectiveness against targeted systems.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story