Back to News
Market Impact: 0.6

Qilin Ransomware Exploits MSPaint and Notepad to Find Sensitive Information

CSCOBLZEGOOGLGOOG
Cybersecurity & Data PrivacyTechnology & InnovationInfrastructure & Defense

Cisco Talos reports the Qilin ransomware group is employing a sophisticated tactic, utilizing legitimate Windows utilities like MSPaint and Notepad for manual data reconnaissance to identify high-value information, thereby bypassing traditional detection mechanisms. This method allows the group, which averages over 40 victims monthly across manufacturing and professional services, to maximize data exfiltration before encryption, leveraging tools such as Cyberduck for cloud-based exfiltration. The evolving threat underscores heightened data breach risks for enterprises, necessitating robust cybersecurity investments in network segmentation, legitimate application abuse monitoring, and immutable backups to mitigate significant financial and operational exposure.

Analysis

Cisco Talos has identified a significant evolution in the Qilin ransomware group's tactics, leveraging legitimate Windows utilities like MSPaint and Notepad for manual data reconnaissance. This sophisticated approach allows attackers to bypass traditional detection mechanisms, focusing on maximizing data exfiltration before deploying encryption. The group has maintained operations since July 2022, impacting over 40 victims monthly as of H2 2025, primarily in manufacturing (23%) and professional services (18%). Qilin's post-compromise workflow involves credential harvesting via tools like Mimikatz, data packaging with WinRAR, and subsequent manual file inspection. Exfiltration is facilitated by the open-source tool Cyberduck, uploading to cloud services such as Backblaze (BLZE), which further obfuscates activity within trusted domains. This Ransomware-as-a-Service (RaaS) model has a global reach, affecting countries like the US, UK, and Germany, with suspected Eastern European or Russian-speaking origins. The strongly negative sentiment (-0.75) surrounding this evolving threat underscores heightened cybersecurity risks for enterprises. While Backblaze (BLZE) faces negative sentiment (-0.4) due to its services being exploited in exfiltration, Cisco (CSCO) exhibits positive sentiment (0.5), likely reflecting its role in threat intelligence and potential for increased demand for its security solutions. Organizations are advised to implement robust network segmentation, multi-factor authentication, and immutable backups to counter these advanced evasion techniques.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.75

Ticker Sentiment

BLZE-0.40
CSCO0.50
GOOG0.00
GOOGL0.00

Key Decisions for Investors

  • Investors should reassess the cybersecurity postures of portfolio companies, focusing on their ability to detect legitimate application abuse and implement robust network segmentation.
  • Consider potential increased demand for advanced cybersecurity solutions, which could benefit providers like Cisco (CSCO) given its positive sentiment and Talos's expertise in threat intelligence.
  • Monitor companies like Backblaze (BLZE) for potential reputational risk or increased scrutiny due to their services being exploited in ransomware exfiltration activities.