Cisco Talos: Qilin EDR killer infection chain

Reported 02 Apr 2026 by otx · Severity: medium

Endpoint detection and response (EDR) tools are widely deployed and far more capable than traditional antivirus. As a result, attackers use EDR killers to disable or bypass them. The malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain