The Containment Era is here. →Explore

Executive Summary

In early to mid-2025, the notorious Qilin ransomware group (also known as Agenda/Gold Feather/Water Galura) executed a wave of aggressive hybrid cyberattacks, combining Linux-targeting ransomware payloads with a sophisticated BYOVD (Bring Your Own Vulnerable Driver) exploit. The attacks leveraged unpatched vulnerabilities to gain initial access, followed by lateral movement across multi-cloud and on-premises environments. Once inside, Qilin deployed encryption routines across both Windows and Linux servers, exfiltrated sensitive business data, and posted victim details on its dark web leak site, with attack volumes peaking at over 100 cases in June 2025. Organizations across healthcare, finance, and manufacturing were among those affected, experiencing significant operational disruptions, data exposure risks, and costly recovery processes.

The rise of cross-platform ransomware with BYOVD techniques demonstrates attackers' growing technical sophistication and ability to evade traditional defenses. As ransomware-as-a-service (RaaS) operations like Qilin accelerate, organizations face increasing regulatory scrutiny and must enhance cloud, endpoint, and network segmentation strategies to defend against such adaptive threats.

Why This Matters Now

This incident underscores the urgent need for robust east-west traffic security, zero trust segmentation, and real-time threat detection, as attackers increasingly exploit hybrid-cloud environments with advanced techniques. The Qilin operation reflects a broader industry trend: ransomware groups adopting multi-platform tools and exploiting overlooked vulnerabilities, dramatically raising the stakes for critical infrastructure and regulated industries.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attacks highlighted weaknesses in east-west traffic controls, real-time threat detection, and lack of segmentation across hybrid environments, undermining NIST, PCI, and HIPAA requirements.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing Zero Trust segmentation, east-west traffic controls, egress policy enforcement, and threat detection through CNSF-aligned capabilities would have significantly limited the adversary's ability to move laterally, exfiltrate data, or execute ransomware in this hybrid attack scenario.

Initial Compromise

Control: Inline IPS (Suricata)

Mitigation: Prevented exploitation of known vulnerable drivers or suspicious ingress exploits.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Alerted on abnormal privilege changes or host posture deviations.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Blocked unauthorized movement between workloads, namespaces, or service identities.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Detected and blocked C2 traffic via URL and egress filtering.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented unauthorized data exfiltration via outbound controls.

Impact (Mitigations)

Provided early detection and automated response to ransomware-like behaviors.

Impact at a Glance

Affected Business Functions

  • Manufacturing Operations
  • Professional Services
  • Wholesale Trade
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive manufacturing designs, client data in professional services, and wholesale trade agreements.

Recommended Actions

  • Enforce Zero Trust Segmentation to isolate workloads, block lateral ransomware movement, and restrict container/pod communications.
  • Deploy Inline IPS and cloud firewall controls to inspect, detect, and block exploitation and command-and-control traffic early in the attack chain.
  • Implement strict egress policy enforcement to monitor and filter unauthorized data transfers and prevent exfiltration paths.
  • Operationalize multicloud visibility and behavioral analytics for rapid anomaly detection across hybrid workloads and Kubernetes clusters.
  • Continuously update threat signatures and baseline monitoring to identify and respond to ransomware indicators and attack TTPs in real time.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image