Russia-Linked Group Expands Ransomware Threat by Stealing Google Chrome Credentials
by DEM0N_PP - Monday August 26, 2024 at 09:23 AM
#1
The Russia-linked cybercrime group Qilin, believed to be responsible for the June attacks that disrupted several U.K. hospitals, has now escalated its tactics by stealing credentials stored within Google Chrome browsers. This new development adds a surprising and alarming twist to the already dangerous threat posed by ransomware attacks.

Qilin, though a relatively new player in the cybercrime world, has quickly gained notoriety for its Ransomware-as-a-Service (RaaS) operations. The group first emerged in October 2022 and has since been linked to a series of high-profile attacks. The latest analysis by researchers from the Sophos X-Ops team reveals that Qilin has adopted a new tactic that amplifies the damage caused by ransomware attacks.
During a recent investigation, the researchers uncovered that Qilin operators were not only deploying ransomware to cripple their targets but also simultaneously stealing credentials from Google Chrome browsers on certain endpoints within the victim’s network. This dual approach not only deepens the immediate impact of the ransomware attack but also extends the threat by compromising sensitive data and potentially enabling further breaches. This tactic, described by the Sophos X-Ops team as a “bonus multiplier for the chaos already inherent in ransomware situations,” significantly broadens the scope of the attack, putting more organizations at risk. The ability to steal browser-stored credentials allows the attackers to reach beyond the initial target, potentially compromising additional systems and networks.

As Qilin continues to evolve its methods, cybersecurity experts are urging organizations to remain vigilant, particularly in securing endpoints and educating users about the risks of storing sensitive credentials in web browsers. The incident underscores the growing complexity and sophistication of ransomware attacks, highlighting the need for robust, multi-layered security strategies.

Source: https://www.forbes.com/sites/daveywinder...eat-twist/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google suffers data breach in ongoing Salesforce data theft attacks by the @ShinyHunt lulagain 1 57 6 hours ago
Last Post: Inexorable_Baer
  Hacker extradited to US for stealing $3.3 million from taxpayers lulagain 0 35 6 hours ago
Last Post: lulagain
  Akira ransomware abuses CPU tuning tool to disable Microsoft Defender lulagain 0 31 6 hours ago
Last Post: lulagain
  New EDR killer tool used by eight different ransomware groups lulagain 0 45 6 hours ago
Last Post: lulagain
  SafePay ransomware threatens to leak 3.5TB of Ingram Micro data lulagain 2 234 08-05-2025, 04:00 AM
Last Post: xhuimix

Forum Jump:


 Users browsing this thread: 1 Guest(s)