Story perspectives
Qilin Ransomware Evades Security Using Windows Subsystem for Linux
10/30/2025
22 4
1 of 1
Story summary
- Qilin ransomware uses Windows Subsystem for Linux (WSL) to run Linux encryptors on Windows systems, evading traditional security measures.
- Trend Micro researchers found attackers use WSL to execute ELF binaries and bypass Windows-focused EDR tools.
- This method enables Linux-based ransomware to run on Windows while avoiding detection.
- Qilin has operated since 2022 as a ransomware-as-a-service, targeting healthcare and government sectors, including the 2024 Synnovis incident disrupting NHS services.
