Sophos X-Ops reported that a Qilin ransomware intrusion used a malicious Active Directory Group Policy Object (GPO) to harvest credentials stored in Google Chrome before encrypting systems. The attack began with compromised credentials used against a VPN portal that lacked multifactor authentication, after which the attackers spent 18 days in the environment moving laterally, reaching a domain controller, and modifying the default domain policy. They deployed a PowerShell script named IPScanner.ps1 and a batch file, logon.bat, through logon policy to collect browser credential data from multiple endpoints.
The stolen data was written to the SYSVOL share in files organized by hostname, allowing the attackers to gather credentials across the domain for more than three days before exfiltrating the results, deleting the files, and clearing event logs. The same GPO mechanism was later used to create a scheduled task that downloaded and executed Qilin ransomware. Sophos warned that the operation increased downstream risk because browser-stored passwords could expose third-party accounts beyond the victim organization, and recommended MFA and dedicated password managers instead of storing credentials in browsers.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos X-Ops reported the July 2024 incident and detailed how Qilin operators used malicious Group Policy to harvest Chrome-stored credentials before ransomware deployment. The report also warned that the tactic could expose third-party accounts beyond the directly affected organization.
After leaving the credential-harvesting GPO active for more than three days, the attackers exfiltrated the collected data, deleted the files, and cleared event logs. They then used Group Policy again to create a scheduled task that downloaded and executed Qilin ransomware.
During the July 2024 incident, the attackers modified the default domain policy on a domain controller to deploy a malicious logon GPO. The GPO used IPScanner.ps1 and logon.bat to collect Google Chrome credential data from multiple endpoints and write it to the SYSVOL share by hostname.
In July 2024, attackers obtained access to the victim environment using compromised credentials through a VPN portal that did not have multifactor authentication enabled. Sophos said the intrusion then persisted in the environment for 18 days before later stages of the attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.