Ransomware hackers are now running Linux encryptions in Windows to remain undetected


  • Qilin ransomware uses WSL to run Linux encryptions stealthily on Windows systems
  • Attackers bypass Windows defenses by executing ELF binaries in WSL environments
  • EDR tools miss WSL-based threats, leaving critical sectors vulnerable to Qilin’s extortion campaigns

Ransomware hackers have been seen running Linux encryptions inside Windows in an attempt to avoid detection by security tools, experts have found.

Researchers at Trend Micro reported observing the Qilin ransomware operation running the Windows Subsystem for Linux (WSL) feature in compromised endpoints.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top