BushidoUK ToolMatrix CommunityReports: CR-012-Qilin-April-2023

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United Kingdom
Sector
Manufacturing
Confianza
high
70
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

2IOCs
0TTPs
bushidoukActor
United KingdomPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Key Points

  • Source: CommunityReports/CR-012-Qilin-April-2023.md
  • BushidoUK Tool Matrix

CommunityReports: CR-012-Qilin-April-2023.md

Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Community Report 0013 - Qilin June 2022

Contributor Details

- Real Name: N/A

- Online Handle / Links to profiles: @knappresearchlb

- Employer: Private, Threat Intelligence Lead

- Affiliations: Ransom-ISAC

---

Adversary

- Named adversary: Qilin Ransomware

---

Incident Details

- Time of Incident: April 2023

- Victim Sector: Manufacturing

- Victim Country: Asia Pacific

- Victim Size: Unknown

- Victim Name: Unknown

---

Observed Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| | | | | Cobalt Strike | Used SMB, RDP, WMI for lateral movement in network| | MEGA cloud storage (30GB)|

---

Indicators of Compromise (IOCs)

| Indicator | Description |

| --------------- | ---------------------------------------------------------------- |

| 184.168.123.0/24 | Repeated connections over the HTTP and SSL protocol to multiple newly observed IPs located in the 184.168.123.0/24 range were observed, indicating C2 connectivity. |

#### Any Related Sources

-

| Date Published | Report |

|---|---|

| 4/7/2024 | https://www.darktrace.com/blog/a-busy-agenda-darktraces-detection-of-qilin-ransomware-as-a-service-operator |

| | |

``mermaid

flowchart TD;

A[Qilin Ransomware] -->|target| B(Geo: Asia Pacific

Sector: Manufacturing

Size: Unknown);

B --> C{Tools};

C -->|OffSec| H[1];

C -->|Networking| I[3];

C -->|Exfiltration| K[1];

``

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix CommunityReports: CR-012-Qilin-April-2023
United Kingdom
Capability
Report
Filtracion: 30 GB
Infrastructure
184.168.123.0
www.darktrace.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

16 enlaces

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
IP 184.168.123.0 Extraido del contenido VT OffSec SOCRadar
Domain www.darktrace.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes