Ransomware Group intelligence
Qiulong
InactiveTrack Qiulong with 8 published victims and 1 known leak locations in a single intelligence view.
Overview
Qiulong is tracked by Breach House as a ransomware group with 8 published victims.
Brazil is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 3h ago | 62brsjf2w77ihz5paods33cdgqnon54gjns5nmag3hmqv6fcwamtkmad.onion |
Top Activity Sectors (3)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Qiulong, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: qiulong executes PowerShell scripts to spread payloads and disable security tools across compromised healthcare systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: qiulong leverages registry run keys to maintain persistence after initial infection in networked environments.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: qiulong disables antivirus and monitoring tools using registry modifications to ensure encryption proceeds undetected.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: qiulong manipulates boot sequences to safely bypass recovery mechanisms during system initialization.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: qiulong encodes victim files with symmetric encryption keys before demanding ransom payments.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: qiulong deletes Volume Shadow Copies and backup files via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: qiulong performs remote system discovery to map internal networks and identify additional targets for lateral movement.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: qiulong scans network shares to discover victim directories and identify files suitable for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: qiulong encrypts patient records and pharmaceutical databases using custom ransomware binaries for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: qiulong invokes system recovery inhibitors to block endpoint protection services from restoring compromised assets.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (8)
Search, filter and paginate the victim timeline for Qiulong. Showing 1–8 of 8.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.concisa.eng.br id13145 View details | Brazil | Communication / Marketing | ||
|
Com duas décadas de atuação em obras de pavimentação, saneamento, asfalto e terraplenagem, a Concisa Obras de Infraestrutura tornou-se referência no sul do Brasil pela qualidade dos serviços e pela transparência com que conduz seus negócios nos segmentos público e privado. Zoominfo: https://www.zoominfo.com/c/concisa-todos/562608830 CEO: Danilo ConteOffice Main Phone: (49) 3323-9591 DATA SIZE: 30GB CEO PERSONAL DOCUMENT: |
|||||
| Ransomware | www.indigoent.ca id12785 View details | Canada | Healthcare / Pharma | ||
|
Indigo ENT Group is a company that operates in the Hospital & Health Care industry. The company is headquartered in Coquitlam, British Columbia, Canada. Zoominfo: https://www.zoominfo.com/c/indigo-ent-group/448092524 Office Main Phone: 604-941-8474 Email: [email protected] Doctors: Dr. Dewji, Dr. Gooi, Dr. Mah In the past few weeks, our group has been operating within the network of Indigo EST, stealing thousands of personal, confidential, and PHI, & PII data of patients. This is the first warning. Samples: |
|||||
| Ransomware | hospitalescultural.com.br id12173 View details | Brazil | Healthcare / Pharma | ||
|
No Hospital Escultural, acreditamos que cada mulher é uma obra-prima em potencial, esperando para ser revelada em toda sua glória. Liderados pelos renomados Dr. Eder Damacena e Dr. Eisenhower Damascena, nós nos especializamos em um espectro abrangente de procedimentos cirúrgicos e não-cirúrgicos, sempre com um toque de arte e um compromisso absoluto com a autenticidade. Hospital Escultural is a Brazilian hospital specializing in plastic surgery. CEO: Dr. Eisenhower Fonseca Damascena Business email: [email protected]: + 55 (62) 3225-2012 Data volume: 50 GB Data description: DATA WILL BE AVAILABLE SOON.CONTACT US BEFORE IS TOO LATE |
|||||
| Ransomware | hominemclinic.com.br id12133 View details | Brazil | Healthcare / Pharma | ||
|
We are a medical clinic specialized in male sexual health care, focusing on the treatment of erectile dysfunction, premature ejaculation and andropause. Message to all men with sexual problems who are Hominem patients: THIS CLINIC DOES NOT PROTECT YOUR DATA AND YOUR PRIVACY, AND SOON EVERYONE WILL KNOW ABOUT YOUR PROBLEMS. In the past month, numerous attempts at contact were made, resulting in a total of zero responses and significant negligence on the part of the clinic’s staff. If silence persists, soon all friends and family of the patients will discover their sexual problems. CEO: Dr. Bruno Salomão Business email: [email protected] Phone: : (31) 99351-4715 Data volume: 5 GB Data description: |
|||||
| Ransomware | www.drwilliansegalin.com.br id12120 View details | Brazil | Healthcare / Pharma | ||
|
Yes, another outlaw plastic surgeon, who does not protect his patients’ privacy safely.Dr. Willian, if you care about your patients’ data and privacy, stop driving your Mustang around like a negligent doctor and avoid remaining silent. O Dr. Willian atua como Cirurgião Plástico em Passo Fundo, Frederico Westphalen e Serafina Corrêa dedicando-se as áreas de Cirurgia Estética, Reconstrutora e Implante capilar. Dr. Willian works as a Plastic Surgeon in Passo Fundo, Frederico Westphalen and Serafina Corrêa, dedicating himself to the areas of Aesthetic, Reconstructive Surgery and Hair Implants. Sua titulação é reconhecida pela Sociedade Brasileira de Cirurgia Plástica (SBCP), Associação Médica Brasileira (AMB) ,Conselho Federal de Medicina. (CRM) e Associação Brasileira de Cirurgia da Restauração Capilar ( ABCRC ). CEO: Willian Segallin Business email: [email protected] Phone: : +5554999200030 Data volume: 20 GB Data description: DATA WILL BE PUBLISHED SOON |
|||||
| Ransomware | draandrearechia.com.br id12113 View details | Brazil | Healthcare / Pharma | ||
|
Dr. Andrea Rechia is another Brazilian plastic surgeon who doesn’t care about the data and privacy of her patients. Numerous attempts were made to contact her; however, she chose to remain silent instead of protecting her patients’ privacy. Somos uma Clínica de Cirurgia Plástica com 15 anos de experiência e atuação na Região Central do Estado. Focamos no atendimento de qualidade, proporcionando o bem-estar e a melhora da auto-estima através do compromisso com a segurança e a qualidade de nosso trabalho. CEO: Dr. Andrea Rechia Business email: [email protected] Phone: WhatsApp: + 55 (51) 9 9812-1314 Data volume: 30 GB Data description: 2GB OF SAMPLES: https://mega.nz/folder/V*********#onogZ_SskDAIhD_rQtK8dA [+] Password found !!!URL: javascript:void(0);Login: [email protected]: Clinica1408!.[+] Password found !!!URL: https://login.live.com/Login: [email protected]:[+] Password found !!!URL: https://seguro.unimedsm.com.br/tiss/index_login.phpLogin: 24952Password: a152349[+] Password found !!!URL: https://experimente.contaazul.com/form-trial/Login: [email protected]: Eutenho46.[+] Password found !!!URL: https://lis.labimed.com.br/shift/lis/labimed/elis/s01.iu.web.Login.clsLogin: P368130Password: 1HD36 |
|||||
| Ransomware | www.rosalvoautomoveis.com.br id12086 View details | Brazil | Other | ||
|
A Rosalvo Automóveis foi fundada em 1988 com o objetivo de revolucionar o conceito de comercialização de veículos semi-novos. Data Available Soon |
|||||
| Ransomware | www.drlincoln.com.br id12085 View details | Brazil | Healthcare / Pharma | ||
|
If you are a patient of Dr. Lincoln Graça Neto, you should know that he doesn’t care about your data and your privacy. O consultório fica localizado na cidade de Curitiba no Batel, bairro nobre da capital paranaense, de fácil acesso e com moderna e agradável estrutura física. Possui ampla sala de espera, sala de consulta médica, duas salas de exame, estúdio fotográfico e administração. Para sua comodidade possuímos também convênio com o estacionamento ao lado. Dr. Lincoln is a Brazilian clinic specializing in plastic surgery CEO: Dr. Lincoln Graça Neto Business email: [email protected] Phone:+55 41 99994 2479 Data volume: 9 GB Data description: Download: https://mega.nz/folder/9*********#ZxPRh7ThnTZ-Y12izAOT9Q https://mega.nz/folder/A*********#bR2cF7WKd4qX3wNzT2ZoQw https://mega.nz/folder/N*********#N16qJ4h_uDp8Xny7ZxiCkw https://mega.nz/folder/I*********#wVDE1cpjha2DOcaHWzjB9A https://mega.nz/folder/c*********#T8xblHZh0jl4nd3SU_aOoQ |
|||||