Executive Summary
In early to mid-2025, the notorious Qilin ransomware group (also known as Agenda/Gold Feather/Water Galura) executed a wave of aggressive hybrid cyberattacks, combining Linux-targeting ransomware payloads with a sophisticated BYOVD (Bring Your Own Vulnerable Driver) exploit. The attacks leveraged unpatched vulnerabilities to gain initial access, followed by lateral movement across multi-cloud and on-premises environments. Once inside, Qilin deployed encryption routines across both Windows and Linux servers, exfiltrated sensitive business data, and posted victim details on its dark web leak site, with attack volumes peaking at over 100 cases in June 2025. Organizations across healthcare, finance, and manufacturing were among those affected, experiencing significant operational disruptions, data exposure risks, and costly recovery processes.
The rise of cross-platform ransomware with BYOVD techniques demonstrates attackers' growing technical sophistication and ability to evade traditional defenses. As ransomware-as-a-service (RaaS) operations like Qilin accelerate, organizations face increasing regulatory scrutiny and must enhance cloud, endpoint, and network segmentation strategies to defend against such adaptive threats.
Why This Matters Now
This incident underscores the urgent need for robust east-west traffic security, zero trust segmentation, and real-time threat detection, as attackers increasingly exploit hybrid-cloud environments with advanced techniques. The Qilin operation reflects a broader industry trend: ransomware groups adopting multi-platform tools and exploiting overlooked vulnerabilities, dramatically raising the stakes for critical infrastructure and regulated industries.
Attack Path Analysis
The Qilin ransomware group gained initial access, likely exploiting a Linux vulnerability or misconfigured service via BYOVD (Bring Your Own Vulnerable Driver). After foothold, they escalated privileges to gain persistence and control, then moved laterally within hybrid or multi-cloud workloads using east-west communications and potentially targeting Kubernetes environments. They established command and control to coordinate activity and deploy ransomware payloads, filtering traffic to evade detection. Sensitive data was systematically exfiltrated, likely through encrypted or unfiltered egress channels. Finally, they executed impactful ransomware actions, encrypting data and disrupting operations across Linux workloads.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited a vulnerable Linux system or misconfigured cloud workload, possibly leveraging BYOVD exploits or exposed APIs for initial ingress.
Related CVEs
CVE-2024-21762
CVSS 9.8An out-of-bounds write vulnerability in Fortinet FortiOS allows remote attackers to execute arbitrary code via crafted requests.
Affected Products:
Fortinet FortiOS – < 7.0.12, < 7.2.5
Exploit Status:
exploited in the wildCVE-2024-23113
CVSS 9.8An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to access system resources.
Affected Products:
Fortinet FortiOS – < 7.0.12, < 7.2.5
Exploit Status:
exploited in the wildCVE-2023-27532
CVSS 7.5A missing authentication vulnerability in Veeam Backup & Replication allows remote attackers to access backup infrastructure.
Affected Products:
Veeam Backup & Replication – < 11.0.1.1261
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Data Encrypted for Impact
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Exploitation for Defense Evasion
Application Layer Protocol: Web Protocols
Exfiltration Over Alternative Protocol
Disk Wipe
Impair Defenses
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication and Access Control
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 9
CISA ZTMM 2.0 – Comprehensive Account Monitoring
Control ID: Identity Pillar: 1.1
NIS2 Directive – Incident Handling, Prevention, and Resilience
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Qilin ransomware's hybrid Linux/Windows attack vectors severely threaten patient data systems, requiring enhanced east-west traffic security and encrypted communications compliance.
Financial Services
Banking systems face critical exposure to Qilin's BYOVD exploits and lateral movement capabilities, necessitating zero trust segmentation and egress security controls.
Government Administration
Public sector infrastructure vulnerable to Qilin's 100+ monthly attacks, demanding multicloud visibility, threat detection, and secure hybrid connectivity for critical operations.
Higher Education/Acadamia
Educational institutions' diverse IT environments create attack surfaces for Qilin ransomware, requiring Kubernetes security and cloud-native security fabric implementations.
Sources
- Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attackhttps://thehackernews.com/2025/10/qilin-ransomware-combines-linux-payload.htmlVerified
- Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attackhttps://cyberwarzone.com/2025/10/27/qilin-ransomware-combines-linux-payload-with-byovd-exploit-in-hybrid-attack/Verified
- Threat Actor | FortiGuard Labshttps://www.fortiguard.com/threat-actor/6254/qilin-ransomwareVerified
- Qilin Ransomware: Tactics & Attack Methodshttps://cybelangel.com/blog/qilin-ransomware-tactics-attack/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust segmentation, east-west traffic controls, egress policy enforcement, and threat detection through CNSF-aligned capabilities would have significantly limited the adversary's ability to move laterally, exfiltrate data, or execute ransomware in this hybrid attack scenario.
Control: Inline IPS (Suricata)
Mitigation: Prevented exploitation of known vulnerable drivers or suspicious ingress exploits.
Control: Multicloud Visibility & Control
Mitigation: Alerted on abnormal privilege changes or host posture deviations.
Control: Zero Trust Segmentation
Mitigation: Blocked unauthorized movement between workloads, namespaces, or service identities.
Control: Cloud Firewall (ACF)
Mitigation: Detected and blocked C2 traffic via URL and egress filtering.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented unauthorized data exfiltration via outbound controls.
Provided early detection and automated response to ransomware-like behaviors.
Impact at a Glance
Affected Business Functions
- Manufacturing Operations
- Professional Services
- Wholesale Trade
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive manufacturing designs, client data in professional services, and wholesale trade agreements.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to isolate workloads, block lateral ransomware movement, and restrict container/pod communications.
- • Deploy Inline IPS and cloud firewall controls to inspect, detect, and block exploitation and command-and-control traffic early in the attack chain.
- • Implement strict egress policy enforcement to monitor and filter unauthorized data transfers and prevent exfiltration paths.
- • Operationalize multicloud visibility and behavioral analytics for rapid anomaly detection across hybrid workloads and Kubernetes clusters.
- • Continuously update threat signatures and baseline monitoring to identify and respond to ransomware indicators and attack TTPs in real time.



