Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Feb 22, 2024 | Updated Aug 04, 2025

Ransom:Linux/Qilin.A!MTB

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Ransom:Linux/Qilin.A!MTB, a less sophisticated predecessor to Ransom:Linux/Qilin!rfn, is a ransomware for Linux/ESXi as part of a Qilin ransomware-as-a-service (RaaS) campaign. In comparison to its successor, it features different code, tactics, and detection profiles. In addition to being just a ransomware operation (using a .onion payment portal) it also threatens data leaks via TOR, which could be considered very damaging to the confidentiality of information on infected devices. It exploits a known vulnerability CVE-2023-27532 (credential theft). 

The !MTB suffix denotes Microsoft Threat Behavior, a signature-based identification, as this earlier version of Qilin uses AES-256/RSA-4096 encryption of targeted files on a Linux/ESXi device vs the dual-layer (ChaCha20 + AES-256 encryption used by Ransom:Linux/Qilin!rfn 

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help. 

Follow us