Ransomware hackers are now running Linux encryptors in Windows to avoid detection


  • Qilin ransomware uses WSL to stealthily run Linux encryptors on Windows systems
  • Attackers bypass Windows defenses by running ELF binaries in WSL environments.
  • EDR tools ignore WSL-based threats, leaving critical sectors vulnerable to Qilin extortion campaigns

Ransomware hackers have been spotted running Linux encryptors in Windows in an attempt to avoid detection by security tools, experts have discovered.

Trend Micro researchers reported observing the operation of Qilin ransomware running Windows Subsystem for Linux (WSL) functionality on compromised endpoints.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top