404. Qilin’s Data Exfiltration Toolkit Updated
Hello everyone!
Today, data exfiltration has become a standard stage in almost every ransomware attack. While threat actors often rely on the same set of tools, there are occasional exceptions.
According to an Arctic Wolf Labs report, operators behind the Qilin ransomware used Proton Drive for data exfiltration. Proton Drive is a cloud storage service developed by the Swiss company Proton and designed with privacy in mind. Its key feature is end-to-end encryption, meaning files are encrypted on the user's device before they are uploaded to the cloud.
Of course, Proton Drive can be used legitimately within enterprise environments. However, it can also serve as an early indicator of ransomware activity, making it a useful candidate for threat hunting.
event_type: "processcreatewin"
AND
proc_file_productname: "Proton Drive"
See you soon!

Comments
Post a Comment