Qilin Ransomware Hits Valu-Trac Investment Management Firm
Incident Date:
November 1, 2024
Overview
Title
Qilin Ransomware Hits Valu-Trac Investment Management Firm
Victim
Valu-Trac Investment Management
Attacker
Qilin
Location
First Reported
November 1, 2024
Qilin Ransomware Group Targets Valu-Trac Investment Management
Valu-Trac Investment Management Limited, a prominent UK-based financial services firm, has recently been targeted by the notorious Qilin ransomware group. This attack underscores the persistent threat ransomware poses to financial institutions, highlighting vulnerabilities within the sector.
About Valu-Trac Investment Management
Established in 1989, Valu-Trac Investment Management Limited is a mid-sized company with an estimated annual revenue of £5.3 million. The firm specializes in investment management services, including fund administration and accounting, and acts as an Authorized Corporate Director (ACD) for UK-authorized funds. Valu-Trac supports approximately 50 sponsors and investment managers, overseeing more than 150 investment funds. Their commitment to stewardship and responsible investment practices aligns with industry standards, making them a key player in the financial sector.
Details of the Ransomware Attack
The Qilin group, known for its sophisticated ransomware-as-a-service model, claimed responsibility for the attack on Valu-Trac. The breach involved unauthorized access and encryption of sensitive data, with Qilin releasing images purportedly containing personally identifiable information from Valu-Trac's systems. This incident highlights the group's use of double extortion tactics, where data encryption is coupled with data theft to pressure victims into paying a ransom.
Qilin Ransomware Group Profile
Qilin, also known as Agenda, emerged in 2022 and has since become a significant threat in the ransomware landscape. The group operates by providing affiliates with advanced ransomware tools, allowing for highly customizable attacks. Qilin's ransomware, initially developed in Golang and later rewritten in Rust, targets Windows, Linux, and VMware ESXi environments. Their focus on cross-platform adaptability and advanced encryption techniques distinguishes them from other ransomware groups.
Potential Vulnerabilities and Attack Vectors
Qilin's attack on Valu-Trac likely exploited vulnerabilities in the company's IT infrastructure. The group is known for using spear phishing and exploiting vulnerabilities in Citrix ADC, RDP, and VMware ESXi to gain initial access. Once inside, they employ tools like Cobalt Strike for lateral movement and data exfiltration. Valu-Trac's reliance on virtualized systems and extensive data handling may have made them an attractive target for Qilin's sophisticated tactics.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.