The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools. The ransomware first launched as "Agenda" in August 2022, rebranding to Qilin by September and continuing to operate under that name to this day. Qilin has become one of the most active ransomware operations, with new research from Trend Micro and Cisco Talos stating that the cybercrime gang has attacked more than 700 victims across 62 countries this year. Both firms say the group has become one of the most active ransomware threats worldwide, publishing over 40 new victims per month in the second half of 2025. Both cybersecurity firms report that Qilin affiliates use a mix of legitimate programs and remote management tools to breach networks and steal credentials, including applications such as AnyDesk, ScreenConnect, and Splashtop for remote access, and Cyberduck and WinRAR for data theft. The threat actors also use common built-in Windows utilities, such as Microsoft Paint (mspaint.exe) and Notepad (notepad.exe), to inspect documents for sensitive data before stealing them. Both Trend Micro and Talos also observed Qilin affiliates performing Bring Your Own Vulnerable Driver (BYOVD) attacks to disable security software before launching encryptors. The attackers deployed signed but vulnerable drivers, such as eskle.sys, to terminate antivirus and EDR processes, and used DLL sideloading to drop additional k...
Qilin ransomware abuses WSL to run Linux encryptors in Windows
BleepingComputer
·Lawrence Abrams
·Published Oct 28, 2025
·Updated
Affected Software
7 affected components
Microsoft Windows
Microsoft Windows Subsystem For Linux
AnyDesk AnyDesk
ScreenConnect ScreenConnect
Splashtop Splashtop
Cyberduck Cyberduck
WinRAR WinRAR
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Qilin ransomware exploits Windows Subsystem for Linux (WSL) to run Linux-based encryptors on Windows systems.
2
What security implications are discussed regarding Qilin ransomware?
The article highlights the potential for Qilin ransomware to evade traditional security measures due to its use of WSL.
3
What was the previous name of Qilin ransomware before it was rebranded?
Qilin ransomware was initially launched as 'Agenda' in August 2022.
4
Which operating systems or software are affected by this ransomware?
Affected products include Microsoft Windows and Microsoft Windows Subsystem for Linux.
5
What types of remote access tools might be at risk according to the article?
The ransomware may pose risks to remote access tools such as AnyDesk, ScreenConnect, Splashtop, Cyberduck, and WinRAR.