Drooid Logo
Back to today’s briefing

Story perspectives

Qilin Ransomware Evades Security Using Windows Subsystem for Linux

10/30/2025

22 4

1 of 1

Story summary
  • Qilin ransomware uses Windows Subsystem for Linux (WSL) to run Linux encryptors on Windows systems, evading traditional security measures.
  • Trend Micro researchers found attackers use WSL to execute ELF binaries and bypass Windows-focused EDR tools.
  • This method enables Linux-based ransomware to run on Windows while avoiding detection.
  • Qilin has operated since 2022 as a ransomware-as-a-service, targeting healthcare and government sectors, including the 2024 Synnovis incident disrupting NHS services.