Qilin Ransomware Hits Valu-Trac Investment Management Firm

Incident Date:

November 1, 2024

World map

Overview

Title

Qilin Ransomware Hits Valu-Trac Investment Management Firm

Victim

Valu-Trac Investment Management

Attacker

Qilin

Location

Fochabers, United Kingdom

, United Kingdom

First Reported

November 1, 2024

Qilin Ransomware Group Targets Valu-Trac Investment Management

Valu-Trac Investment Management Limited, a prominent UK-based financial services firm, has recently been targeted by the notorious Qilin ransomware group. This attack underscores the persistent threat ransomware poses to financial institutions, highlighting vulnerabilities within the sector.

About Valu-Trac Investment Management

Established in 1989, Valu-Trac Investment Management Limited is a mid-sized company with an estimated annual revenue of £5.3 million. The firm specializes in investment management services, including fund administration and accounting, and acts as an Authorized Corporate Director (ACD) for UK-authorized funds. Valu-Trac supports approximately 50 sponsors and investment managers, overseeing more than 150 investment funds. Their commitment to stewardship and responsible investment practices aligns with industry standards, making them a key player in the financial sector.

Details of the Ransomware Attack

The Qilin group, known for its sophisticated ransomware-as-a-service model, claimed responsibility for the attack on Valu-Trac. The breach involved unauthorized access and encryption of sensitive data, with Qilin releasing images purportedly containing personally identifiable information from Valu-Trac's systems. This incident highlights the group's use of double extortion tactics, where data encryption is coupled with data theft to pressure victims into paying a ransom.

Qilin Ransomware Group Profile

Qilin, also known as Agenda, emerged in 2022 and has since become a significant threat in the ransomware landscape. The group operates by providing affiliates with advanced ransomware tools, allowing for highly customizable attacks. Qilin's ransomware, initially developed in Golang and later rewritten in Rust, targets Windows, Linux, and VMware ESXi environments. Their focus on cross-platform adaptability and advanced encryption techniques distinguishes them from other ransomware groups.

Potential Vulnerabilities and Attack Vectors

Qilin's attack on Valu-Trac likely exploited vulnerabilities in the company's IT infrastructure. The group is known for using spear phishing and exploiting vulnerabilities in Citrix ADC, RDP, and VMware ESXi to gain initial access. Once inside, they employ tools like Cobalt Strike for lateral movement and data exfiltration. Valu-Trac's reliance on virtualized systems and extensive data handling may have made them an attractive target for Qilin's sophisticated tactics.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.