PULSE NAME
Cisco Talos: Qilin EDR killer infection chain
WHITE AlienVault 2026-04-02 Modified: 2026-04-02
13
IOCs
MEDIUM VOLUME
Endpoint detection and response (EDR) tools are widely deployed and far more capable than traditional antivirus. As a result, attackers use EDR killers to disable or bypass them. The malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain targeting EDR systems. It can terminate over 300 different EDR drivers from almost every vendor in the market.
Indicators of Compromise (5 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 05aa031a007e2f51e3f48ae2ed1e1fcb 2026-04-02
FileHash-MD5 1305e8b0f9c459d5ed85e7e474fbebb1 2026-04-02
FileHash-MD5 6bc8e3505d9f51368ddf323acb6abc49 2026-04-02
FileHash-MD5 89ee7235906f7d12737679860264feaf 2026-04-02
FileHash-MD5 cf7cad39407d8cd93135be42b6bd258f 2026-04-02