Ransomware hackers now run Linux encryptions on Windows to blend in



  • Qilin ransomware uses WSL to stealthily run Linux encryptors on Windows systems
  • Attackers bypass Windows defenses by running ELF binaries inside WSL environments
  • EDR tools miss WSL-based threats, leaving critical sectors vulnerable to Qilin extortion campaigns

Experts have found that ransomware hackers have been found running Linux encryptions on Windows in an attempt to avoid detection by security tools.

Trend Micro researchers reported observing the operation of Qilin ransomware executing the Windows Subsystem for Linux (WSL) function on compromised endpoints.



Leave a Comment

Your email address will not be published. Required fields are marked *