CERT.at published an advisory and follow-up update on a campaign linking the Qilin ransomware-as-a-service operation to the ZIPLINE malware. The reporting indicates that ZIPLINE is being used as part of Qilin-linked intrusion activity, expanding the tooling associated with the group beyond ransomware deployment and highlighting a broader attack chain tied to the affiliate ecosystem.
The update suggests defenders should treat ZIPLINE as a relevant indicator in investigations involving Qilin activity and review detections, threat hunting, and incident response playbooks accordingly. The paired notices from CERT.at frame the development as an operational update on Qilin’s tradecraft, underscoring that organizations tracking ransomware threats should monitor both the ransomware payload and supporting malware used for access, execution, or post-compromise operations.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
CERT.at published an update to its earlier advisory on ZIPLINE and Qilin RaaS. The reference indicates a follow-up development but does not include substantive details about the changes.
CERT.at published a security advisory concerning ZIPLINE and the Qilin ransomware-as-a-service operation. No further incident details are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.