PULSE NAME
Cisco Talos: Qilin EDR killer infection chain
WHITE AlienVault 2026-04-02 Modified: 2026-04-02
13
IOCs
MEDIUM VOLUME
Endpoint detection and response (EDR) tools are widely deployed and far more capable than traditional antivirus. As a result, attackers use EDR killers to disable or bypass them. The malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain targeting EDR systems. It can terminate over 300 different EDR drivers from almost every vendor in the market.
Indicators of Compromise (4 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 12fcde06ddadf1b48a61b12596e6286316fd33e850687fe4153dfd9383f0a4a0 2026-04-02
FileHash-SHA256 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0 2026-04-02
FileHash-SHA256 7787da25451f5538766240f4a8a2846d0a589c59391e15f188aa077e8b888497 2026-04-02
FileHash-SHA256 bd1f381e5a3db22e88776b7873d4d2835e9a1ec620571d2b1da0c58f81c84a56 2026-04-02