Russia-Linked Group Expands Ransomware Threat by Stealing Google Chrome Credentials
by DEM0N_PP - Monday August 26, 2024 at 09:23 AM
#1
The Russia-linked cybercrime group Qilin, believed to be responsible for the June attacks that disrupted several U.K. hospitals, has now escalated its tactics by stealing credentials stored within Google Chrome browsers. This new development adds a surprising and alarming twist to the already dangerous threat posed by ransomware attacks.

Qilin, though a relatively new player in the cybercrime world, has quickly gained notoriety for its Ransomware-as-a-Service (RaaS) operations. The group first emerged in October 2022 and has since been linked to a series of high-profile attacks. The latest analysis by researchers from the Sophos X-Ops team reveals that Qilin has adopted a new tactic that amplifies the damage caused by ransomware attacks.
During a recent investigation, the researchers uncovered that Qilin operators were not only deploying ransomware to cripple their targets but also simultaneously stealing credentials from Google Chrome browsers on certain endpoints within the victim’s network. This dual approach not only deepens the immediate impact of the ransomware attack but also extends the threat by compromising sensitive data and potentially enabling further breaches. This tactic, described by the Sophos X-Ops team as a “bonus multiplier for the chaos already inherent in ransomware situations,” significantly broadens the scope of the attack, putting more organizations at risk. The ability to steal browser-stored credentials allows the attackers to reach beyond the initial target, potentially compromising additional systems and networks.

As Qilin continues to evolve its methods, cybersecurity experts are urging organizations to remain vigilant, particularly in securing endpoints and educating users about the risks of storing sensitive credentials in web browsers. The incident underscores the growing complexity and sophistication of ransomware attacks, highlighting the need for robust, multi-layered security strategies.

Source: https://www.forbes.com/sites/daveywinder...eat-twist/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  SafePay ransomware threatens to leak 3.5TB of Ingram Micro data lulagain 2 222 08-05-2025, 04:00 AM
Last Post: xhuimix
  Qilin login credentials exposed by competitor DissentDoe 0 163 08-02-2025, 03:03 PM
Last Post: DissentDoe
  Pro-Ukrainian hackers claim massive cyberattack on Russia's Aeroflot icesig 4 379 07-31-2025, 02:37 PM
Last Post: Shadowraser
  The GLOBAL GROUP ransomware gang is claiming responsibility for a breach of Albavisió MalWhere77 2 330 07-30-2025, 09:55 PM
Last Post: osamaladen819191
  BlackSuit ransomware extortion sites seized in Operation Checkmate lulagain 1 278 07-30-2025, 02:47 PM
Last Post: Shadowraser

Forum Jump:


 Users browsing this thread: 1 Guest(s)