Ransomware hackers are now running Linux encryptors in Windows to stay undetected



  • Qilin ransomware uses WSL to run Linux encryptors stealthily on Windows systems
  • Attackers bypass Windows defenses by executing ELF binaries inside WSL environments
  • EDR tools miss WSL-based threats, leaving critical sectors vulnerable to Qilin’s extortion campaigns

Ransomware hackers have been spotted running Linux encryptors in Windows in a bid to avoid detection by security tools, experts have found.

Researchers at Trend Micro reported observing the Qilin ransomware operation running the Windows Subsystem for Linux (WSL) feature in compromised endpoints.


https://cdn.mos.cms.futurecdn.net/9jwoYqPpkcPNa9JuritsPT-640-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img