Ransomware Warning

A ransomware group called Qilin, which carried out a cyberattack on British hospitals in June 2024, is now also responsible for stealing passwords stored in the Google Chrome browser. According to researchers from Sophos X-Ops, this action is unusual for ransomware groups, suggesting shifting cybercriminal strategies.

Qilin is a relatively new group, active for over two years, which gained notoriety after an attack on Synnovis, a supplier of services for the British healthcare system. Until now, they have used a double extortion method, involving data theft, system encryption and threatening to disclose or sell stolen information if the ransom is not paid. However, in the latest attack studied by Sophos, Qilin not only carried out a ransomware attack but also stole authentication data from victims' devices. The group focused on the Google Chrome browser, used by over 65 percent of internet users.

– Credential theft is one of the most effective methods of infiltrating systems by cybercriminals. According to our Active Adversary report, it was the main cause of attacks in the first half of 2024 and played a significant role in many high-profile data breach cases we have seen this year. Qilin went a step further, obtaining information from Google Chrome browsers, where users often store passwords for various accounts. This makes such data extremely valuable to cybercriminals – explains Christopher Budd, director of threat research at Sophos X-Ops.

Credential theft is one of the most serious scenarios in cybersecurity. When criminals obtain passwords and logins, they can take control of bank accounts, emails, social media profiles, and even a company's IT infrastructure. This typically leads to identity theft, financial fraud and leakage of sensitive information, which can involve serious financial losses.

Moreover, stolen data is often used for further attacks or sold on the black market. Even people who were not directly attacked can be at risk if their data is used in other criminal activities.

Both companies and individuals should use password management applications that comply with industry best practices and are regularly tested by independent entities. Using a password manager built into the browser is not a secure solution, as the recent incident shows.

Ransomware groups are constantly adapting their tactics to bypass existing security measures. Therefore, it is important to understand the changing strategies of cybercriminals and adjust protection measures accordingly.