A new Rust variant of Qilin ransomware (Agenda), dubbed Qilin.B, is being used in attacks, with stronger encryption, more detection evasion capabilities, and the ability to disrupt data recovery mechanisms.

Qilin.B was discovered by security researchers , who shared indicators of compromise to aid in early detection.
For encryption, Qilin.B ransomware uses AES-256-CTR with AESNI capabilities for CPUs that support it, speeding up encryption. However, it also maintains ChaCha20 for weaker or older systems. This ensures that strong encryption is available in all cases.
See also: Ransomware gangs use LockBit's notoriety to pressure victims
Qilin.B also incorporates RSA-4096 with OAEP padding to protect the encryption key, making decryption nearly impossible without the private key.
Upon execution, the new Qilin.B ransomware adds an autorun key to the Windows Registry to ensure persistence. It also terminates the following processes to free up critical data for encryption and disable security:
- Veeam
- Windows Volume Shadow Copy Service
- SQL database services
- Sophos
- Acronis Agent
- SAP
Qilin.B targets both local directories and network folders and leaves relevant ransom notes in each targeted directory.
See also: Bug in Mallox Ransomware allows victims to recover files without paying ransom
While we have seen other ransomware with similar capabilities, this is a significant upgrade to the Qilin ransomware. Such an attack can have significant consequences, especially if carried out by an experienced hacking group.
Last August, Sophos revealed that Qilin was developing an information-stealing program to harvest credentials stored in Google Chrome.
Previously, Qilin was used in extremely destructive attacks against major London hospitals, Court Services Victoria in Australia, and the Yanfeng automobile manufacturer.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
See also: Healthcare ransomware attacks are putting lives at risk

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
See also: Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.
Source: www.bleepingcomputer.com
