New ransomware strain discovered that specializes in stealing login information from Chrome browser

A new strain of ransomware called Qilin has been discovered using a relatively sophisticated, highly customizable tactic to steal account login information stored in the Google Chrome browser.

The Sophos X-Ops global security research team observed credential harvesting techniques during its Qilin incident response, indicating an alarming shift in the way this dangerous ransomware strain operates.

Overview of the attack process

The attack analyzed by Sophos researchers began with the Qilin malware successfully accessing the target network using compromised credentials on a VPN gateway without multi-factor authentication (MFA).

This was followed by an 18-day period of malware “hibernation,” suggesting that the hackers had purchased access to the network through an initial access broker (IAB). Qilin likely spent time mapping the network, identifying key assets, and conducting reconnaissance.

After the first 18 days, the malware moves laterally to domain controllers and modifies Group Policy Objects (GPOs) to execute a PowerShell script ('IPScanner.ps1') on all machines logged into the domain network.

This script is executed by a batch script ('logon.bat'), and is also included in the GPO. It is designed to collect login information stored in Google Chrome.

The batch script is configured to run (and trigger a PowerShell script) every time a user logs in to their machine. In parallel, the stolen credentials are saved on the 'SYSVOL' partition under the name 'LD' or 'temp.log'.

New ransomware strain discovered that specializes in stealing login information from Chrome browser

After sending the files to Qilin’s command and control (C2) server, local copies and associated event logs were deleted to conceal the malicious activity. Finally, Qilin deployed the ransomware payload and encrypted data on the compromised machines.

Another GPO and a separate command file ('run.bat') are also used to download and execute the ransomware on all machines in the domain.

New ransomware strain discovered that specializes in stealing login information from Chrome browser

Complexity in defense

Qilin's approach to Chrome credentials sets a troubling precedent that could make protecting against ransomware attacks more difficult.

Because the GPO is applied to all machines in the domain, every device where the user is logged on is subject to the credential collection process.

This means that the script is capable of stealing credentials from all machines across the system, as long as those machines are connected to the domain and have a user logged in during the time the script is running.

Such widespread credential theft can allow hackers to launch follow-up attacks, resulting in a security incident that spans multiple platforms and services, making response efforts much more cumbersome. It also creates a persistent threat that lingers long after the ransomware incident is resolved.

Organizations can mitigate risk by implementing strict policies that prohibit storing secrets in web browsers. Additionally, implementing multi-factor authentication is key to protecting accounts from being taken over, even in the event of a compromised credential.

Finally, implementing principles of least privilege and network segmentation can significantly hinder a threat actor's ability to spread across a compromised network.

Leave a Comment

What Young Riders Should Know About Moving Their Motorcycles Across Cities

What Young Riders Should Know About Moving Their Motorcycles Across Cities

Long-distance travel can involve heavy traffic, changing weather conditions, and rider fatigue. If you are also dealing with the responsibilities of moving home, such as packing belongings or coordinating accommodation, a long ride may add unnecessary pressure to an already busy schedule.

Solving Microsoft Teams Shortcut Error Not Opening

Solving Microsoft Teams Shortcut Error Not Opening

Tired of Microsoft Teams shortcut error preventing you from opening the app? Follow our expert, step-by-step guide with the latest fixes for instant resolution. Works on Windows, Mac & web – no tech skills needed!

Solving Microsoft Teams Task Management Sync Error

Solving Microsoft Teams Task Management Sync Error

Tired of Microsoft Teams Task Management Sync Error halting your workflow? Follow our proven, step-by-step fixes to resolve sync issues fast and restore seamless task collaboration. No tech expertise needed!

Troubleshooting Microsoft Teams Wiki Error Formatting

Troubleshooting Microsoft Teams Wiki Error Formatting

Struggling with Microsoft Teams Wiki Error Formatting? This step-by-step guide reveals proven fixes for common wiki tab issues, ensuring smooth editing and collaboration in Teams. Get back to productive wikis fast!

How to Fix Microsoft Teams Installation Error for Linux

How to Fix Microsoft Teams Installation Error for Linux

Struggling with Microsoft Teams installation error on Linux? Discover step-by-step fixes for Ubuntu, Fedora & more. Resolve dependency issues, crashes, and errors quickly with our ultimate guide. Get Teams running smoothly today!

Solving Microsoft Teams Error Page Not Loading

Solving Microsoft Teams Error Page Not Loading

Struggling with Microsoft Teams "Error Page" not loading? Get step-by-step fixes for desktop, web, and mobile. Solve Microsoft Teams Error Page issues quickly and resume seamless teamwork today.

Solving Microsoft Teams Error Screenshot Issues

Solving Microsoft Teams Error Screenshot Issues

Tired of Microsoft Teams "Error Screenshot" blocking your workflow? Get proven, step-by-step solutions to resolve screenshot errors in Teams instantly and boost productivity. No tech skills needed!

How to Fix Microsoft Teams Error U User

How to Fix Microsoft Teams Error U User

Tired of Microsoft Teams "Error U" User blocking your chats? Get proven, step-by-step fixes to clear cache, reset, and restore seamless collaboration instantly.

Where are Microsoft Teams Registry Keys Located on Windows 11?

Where are Microsoft Teams Registry Keys Located on Windows 11?

Unlock the precise locations of Microsoft Teams registry keys on Windows 11. Step-by-step guide to find, access, and safely tweak them for optimal performance and troubleshooting. Essential for IT pros and Teams enthusiasts.

How to Fix Microsoft Teams Training Error Video Lag

How to Fix Microsoft Teams Training Error Video Lag

Tired of Microsoft Teams "Training Error" Video Lag ruining your meetings? Follow our step-by-step guide with the latest fixes for smooth video calls—no more frustration!

How to Fix Microsoft Teams Error occurred During Sign-In

How to Fix Microsoft Teams Error occurred During Sign-In

Frustrated by Microsoft Teams "Error occurred" during sign-in? Discover proven, step-by-step fixes to get back online fast. Clear cache, reset app, and more for seamless login. Works on Windows, Mac & web.

Troubleshooting Microsoft Teams Call Error Disconnecting

Troubleshooting Microsoft Teams Call Error Disconnecting

Struggling with Microsoft Teams "Call Error" Disconnecting? Discover proven, step-by-step fixes for call drops, network issues, and more. Get back to seamless meetings fast with our expert troubleshooting guide.

How to Fix Microsoft Teams Error 2603: Login Loop Fix

How to Fix Microsoft Teams Error 2603: Login Loop Fix

Stuck in Microsoft Teams Error 2603 login loop? Get proven step-by-step fixes to resolve the issue fast and restore seamless teamwork. Clear cache, reset, reinstall – all covered!

How to Fix Microsoft Teams Voice Call Error

How to Fix Microsoft Teams Voice Call Error

Tired of Microsoft Teams voice call errors? Follow our step-by-step guide to troubleshoot no audio, echo, or call drops. Proven fixes for crystal-clear calls every time.

How to Fix Microsoft Teams Workflows Error Power Automate

How to Fix Microsoft Teams Workflows Error Power Automate

Struggling with Microsoft Teams "Workflows Error" in Power Automate? Discover proven, step-by-step fixes to resolve connection issues, permissions, and more. Get your workflows running smoothly today!