Qiulong is a ransomware group that first emerged around April 2024, characterized by its organized attack strategies and the deployment of custom ransomware, primarily targeting Brazilian organizations. The group's primary motivation is financial gain through double extortion. A distinctive characteristic that sets them apart is their tactic of publishing identity documents of victims' family members to pressure payment, in addition to posting mocking content targeting victims on their data leak sites.
Tecnicas MITRE
T1486, T1566.001, T1203, T1190
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.