Qilin ransomware uses WSL to run Linux encryptors on Windows

Lisa Kern

Cybersecurity researchers have uncovered a tactic by the Qilin ransomware group that exploits Microsoft's Windows Subsystem for Linux (WSL) to execute Linux-based encryption tools on Windows machines. This method allows attackers to bypass many endpoint detection and response (EDR) systems by operating in a Linux sandbox environment that traditional tools often overlook. The technique highlights the growing sophistication of ransomware operations blending operating systems.

Tovuti hii hutumia kuki

Tunatumia kuki kwa uchambuzi ili kuboresha tovuti yetu. Soma sera yetu ya faragha sera ya faragha kwa maelezo zaidi.
Kataa