Qilin – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 21 Aug 2025 18:53:29 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Qilin – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Europol confirms $50,000 Qilin ransomware reward is fake https://earlybirdsinvest.com/europol-confirms-50000-qilin-ransomware-reward-is-fake/ https://earlybirdsinvest.com/europol-confirms-50000-qilin-ransomware-reward-is-fake/#respond Thu, 21 Aug 2025 18:53:29 +0000 https://earlybirdsinvest.com/europol-confirms-50000-qilin-ransomware-reward-is-fake/

Smiley hacker

Europol has confirmed that a Telegram channel impersonating the agency and offering a $50,000 reward for information on two Qilin ransomware administrators is fake. The impostor later admitted it was created to troll researchers and journalists.

“We were also surprised to see this story gaining traction,” Europol told BleepingComputer on Monday. “The announcement didn’t come from us.”

The statement comes after a new Telegram channel called @europolcti was created on August 16th, claiming to offer a $50,000 reward for information on two Qilin ransomware admins known as “Haise” and “XORacle”.

“During the course of ongoing international investigations, we have confirmed that the cybercriminal group Qilin has carried out ransomware attacks worldwide, severely disrupting critical infrastructure and causing significant financial losses,” reads the imposter’s Telegram post.

“We have identified two primary administrators operating under the aliases Haise and XORacle, who coordinate affiliates and oversee extortion activities.”

“We are actively pursuing all available leads in cooperation with international partners.”

“A reward of up to $50,000 is offered for information that directly leads to the identification or location of these administrators.”

Fake Europol CTI post offering Qilin ransomware bounty
Fake Europol CTI post offering Qilin ransomware bounty
Source: BleepingComputer

Haise is believed to be one of the operators of the Qilian ransomware gang, previously recruiting affiliates on the RAMP cybercrime forum.

The Qilin ransomware operation was initially launched as “Agenda” in August 2022. However, by September that year, it had rebranded under the name Qilin, which it continues to use to this day.

The ransomware operation is one of the most active, currently targeting companies worldwide.

However, after Europol confirmed it was fake, a new post appeared on the imposter channel claiming it was created to troll researchers and journalists, some of whom wrote articles about the claims.

“This was so easy to run and fool so called ‘Researchers’ and ‘Journalists’ that just copy stuff.. Thank you all!,” reads the new post.

Post claiming fake reward was to troll researchers and journalists
Post claiming fake reward was to troll researchers and journalists
Source: BleepingComputer

The post was signed by Rey, a hacker previously linked to breaches at Telefonica and Orange Group.

Threat actors had begun trolling Qilin in August 15th posts on a Telegram channel impersonating threat actors from “Scattered Spider”, “ShinyHunters”, and “Lapsus,” where someone had begun calling out Haise and the ransomware operation.

This is not the first time threat actors attempted to mislead the media about cybercrime.

In 2021, a RAMP admin known as ‘Orange’ or ‘boriselcin’ and who ran the “Groove” ransomware site, called on threat actors to attack the USA. This threat actor was later sanctioned by the US for his involvement in three ransomware operations that targeted victims across the United States.

After the media covered this post, including BleepingComputer, the threat actor claimed it was fake and was created to troll and manipulate the media and security researchers.

However, security researchers from McAfee and Intel 471 believe that it was likely the threat actor trying to cover up for a failed ransomware-as-a-service.

In 2023, BleepingComputer receieved a “tip” about an alleged arrest of two Canadian teens over a crypto-theft attack.

While BleepingComputer learned that the news was fake and did not cover the story, we were told it was done to manipulate the media and “troll” the people accused of the theft.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/europol-confirms-50000-qilin-ransomware-reward-is-fake/feed/ 0 54414
Critical Fortinet flaws now exploited in Qilin ransomware attacks https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/ https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/#respond Fri, 06 Jun 2025 14:16:19 +0000 https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/

Qilin

The Qilin ransomware operation has recently joined attacks exploiting two Fortinet vulnerabilities that allow bypassing authentication on vulnerable devices and executing malicious code remotely.

Qilin (also tracked as Phantom Mantis) surfaced in August 2022 as a Ransomware-as-a-Service (RaaS) operation under the “Agenda” name and has since claimed responsibility for over 310 victims on its dark web leak site.

Its victim list also includes high-profile organizations, such as automotive giant Yangfeng, publishing giant Lee Enterprises, Australia’s Court Services Victoria, and pathology services provider Synnovis. The Synnovis incident impacted several major NHS hospitals in London, which forced them to cancel hundreds of appointments and operations.

Threat intelligence company PRODAFT, which spotted these new and partially automated Qilin ransomware attacks targeting several Fortinet flaws, also revealed that the threat actors are currently focusing on organizations from Spanish-speaking countries, but they expect the campaign to expand worldwide.

“Phantom Mantis recently launched a coordinated intrusion campaign targeting multiple organizations between May and June 2025. We assess with moderate confidence that initial access are being achieved by exploiting several FortiGate vulnerabilities, including CVE-2024-21762, CVE-2024-55591, and others,” PRODAFT says in a private flash alert shared with BleepingComputer.

“Our observations indicate a particular interest in Spanish-speaking countries, as reflected in the data presented in the table below. However, despite this regional focus, we assess that the group continues to select its targets opportunistically, rather than following a strict geographical or sector-based targeting pattern.”

PRODAFT Fortinet Qilin ransomware attacks

One of the flaws abused in this campaign, tracked as CVE-2024-55591, was also exploited as a zero-day by other threat groups to breach FortiGate firewalls as far back as November 2024. The Mora_001 ransomware operator has also used it to deploy the SuperBlack ransomware strain linked to the infamous LockBit cybercrime gang by Forescout researchers.

The second Fortinet vulnerability exploited in these Qilin ransomware attacks (CVE-2024-21762) was patched in February, with CISA adding it to its catalog of actively exploited security flaws and ordering federal agencies to secure their FortiOS and FortiProxy devices by February 16.

Almost a month later, the Shadowserver Foundation announced that it had found that nearly 150,000 devices were still vulnerable to CVE-2024-21762 attacks.

Fortinet security vulnerabilities are often exploited (frequently as zero days) in cyber espionage campaigns and for breaching corporate networks in ransomware attacks.

For instance, in February, Fortinet disclosed that the Chinese Volt Typhoon hacking group used two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to deploy the Coathanger custom remote access trojan (RAT) malware, which had been previously used to backdoor a Dutch Ministry of Defence military network.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/feed/ 0 40476