Qilin Ransomware’s Evolving Threat: A New Botnet Alliance
At Alpha Cyber, our threat intelligence division constantly monitors the evolving threat landscape, analyzing attacker behavior, infrastructure, and payload delivery methods.

The Blurring Lines of Cybercrime: How Qilin Ransomware is Using Botnet Infrastructure
At Alpha Cyber, our threat intelligence division constantly monitors the evolving threat landscape, analyzing attacker behavior, infrastructure, and payload delivery methods. In a recent investigation into the Qilin ransomware group, a rapidly emerging player in the ransomware-as-a-service (RaaS) ecosystem. We uncovered a worrying infrastructure overlap that goes beyond typical ransomware operations. Specifically, we found clear signs that Qilin is leveraging external botnet infrastructure to scale its operations and evade detection.
The investigation began with a set of Indicators of Compromise (IOCs) sourced from a trusted threat intelligence feed, the OTX Pulse on Qilin. This feed highlights Qilin’s use of Bring Your Own Vulnerable Driver (BYOVD) attacks. This technique involves deploying legitimately signed but vulnerable drivers to disable security software and gain kernel-level access, a tactic increasingly used by advanced threat actors to bypass endpoint defenses. As we expanded our analysis beyond local IOCs, our team pivoted to examining command-and-control infrastructure associated with this campaign.
During our infrastructure mapping, IP address 216.120.203.26 stood out. It was initially flagged due to behavioral overlap with known Qilin ransomware activity. However, a deeper network analysis revealed that this IP was not functioning like a typical C2 node. Instead, it was engaged in high-volume scanning, automated exploitation, and interaction with Internet of Things (IoT) devices, activity strongly aligned with botnet behavior. Our analysis of the traffic revealed a direct connection to a Mirai botnet, and we were able to identify a specific malware file: k24mdgoqe.exe, with the SHA-256 hash ea6b72c913dbeb6104b98e5fbfa084b0aabf61eac0ca861e22505631e135ac1c. This discovery confirms that Qilin is using botnet infrastructure.

This discovery suggests a disturbing trend: ransomware groups like Qilin are no longer operating within isolated silos. Instead, they are piggybacking on active botnet ecosystems, using compromised IoT devices, third-party servers, and rented infrastructure to launch and mask their attacks. By integrating with distributed botnet operations, Qilin is able to amplify its reach, obscure attribution, and maintain resilience even as defenders attempt to dismantle parts of its infrastructure. This strategy also allows them to deliver ransomware payloads more efficiently, evade IP-based blocking, and continue operations even when takedowns occur.
Qilin itself is a highly modular threat, targeting both Windows and Linux environments with customized payloads built per victim. The group has demonstrated a clear understanding of modern enterprise security stacks, often disabling EDR and AV tools before encrypting systems. In some cases, they’ve been seen stealing data to apply double extortion pressure. With their use of BYOVD and reliance on shared or compromised infrastructure, the group reflects the growing blurring of lines between ransomware actors, botnet operators, and initial access brokers, creating a supply-chain-like model of cybercrime that’s increasingly difficult to disrupt.
What This Means for Your Business
This incident highlights the urgent need for defense-in-depth strategies that go beyond endpoint protection. Traditional perimeter security and basic threat feeds are no longer sufficient when ransomware groups are embedding themselves in globally distributed infrastructures and using sophisticated kill chains. You need real-time infrastructure mapping, cross-domain threat intelligence, and proactive threat hunting to stay ahead of adversaries who are combining the worst of ransomware and botnet tactics.
At Alpha Cyber, we specialize in identifying and disrupting the full attack lifecycle. Our services include infrastructure analysis, dark web monitoring, adversary attribution, and managed threat hunting. We help organizations uncover threats before they reach production environments, empowering security teams to act on intelligence, not just alerts. With tailored threat reports, proactive detection methodologies, and a team of experienced analysts, we equip your organization with the tools to stay resilient in an increasingly hostile digital landscape.
Don’t wait for the breach.
Contact us today to schedule a threat landscape assessment or to learn how we can help secure your infrastructure from ransomware groups exploiting hidden networks and vulnerabilities.



