Qilin Ransomware Hits Valu-Trac Investment Management Firm

Incident Date: Nov 01, 2024

Attack Overview
VICTIM
Valu-Trac Investment Management
INDUSTRY
Finance
LOCATION
United Kingdom
ATTACKER
Qilin
FIRST REPORTED
November 1, 2024

Qilin Ransomware Group Targets Valu-Trac Investment Management

Valu-Trac Investment Management Limited, a prominent UK-based financial services firm, has recently been targeted by the notorious Qilin ransomware group. This attack underscores the persistent threat ransomware poses to financial institutions, highlighting vulnerabilities within the sector.

About Valu-Trac Investment Management

Established in 1989, Valu-Trac Investment Management Limited is a mid-sized company with an estimated annual revenue of £5.3 million. The firm specializes in investment management services, including fund administration and accounting, and acts as an Authorized Corporate Director (ACD) for UK-authorized funds. Valu-Trac supports approximately 50 sponsors and investment managers, overseeing more than 150 investment funds. Their commitment to stewardship and responsible investment practices aligns with industry standards, making them a key player in the financial sector.

Details of the Ransomware Attack

The Qilin group, known for its sophisticated ransomware-as-a-service model, claimed responsibility for the attack on Valu-Trac. The breach involved unauthorized access and encryption of sensitive data, with Qilin releasing images purportedly containing personally identifiable information from Valu-Trac's systems. This incident highlights the group's use of double extortion tactics, where data encryption is coupled with data theft to pressure victims into paying a ransom.

Qilin Ransomware Group Profile

Qilin, also known as Agenda, emerged in 2022 and has since become a significant threat in the ransomware landscape. The group operates by providing affiliates with advanced ransomware tools, allowing for highly customizable attacks. Qilin's ransomware, initially developed in Golang and later rewritten in Rust, targets Windows, Linux, and VMware ESXi environments. Their focus on cross-platform adaptability and advanced encryption techniques distinguishes them from other ransomware groups.

Potential Vulnerabilities and Attack Vectors

Qilin's attack on Valu-Trac likely exploited vulnerabilities in the company's IT infrastructure. The group is known for using spear phishing and exploiting vulnerabilities in Citrix ADC, RDP, and VMware ESXi to gain initial access. Once inside, they employ tools like Cobalt Strike for lateral movement and data exfiltration. Valu-Trac's reliance on virtualized systems and extensive data handling may have made them an attractive target for Qilin's sophisticated tactics.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.