Malware · 166 days ago

Qilin’s msimg32.dll Disables 300+ EDR Drivers to Hide Ransomware Activity

Qilin ransomware uses a malicious DLL named msimg32.dll as part of a multi-stage infection chain designed to disable endpoint detection and response (EDR) systems. This payload terminates over 300 EDR drivers across nearly every vendor, not just to remove protection but to suppress telemetry collection and forensic visibility. It employs kernel object manipulation, structured exception handling (SEH/VEH) obfuscation, and API/syscall bypasses to evade detection and frustrate incident response.

This means traditional endpoint telemetry and EDR logs may be unreliable during an attack. Incident responders should prioritize out-of-band logs, preserve offline images, and treat endpoints with no evidence of compromise as potentially infected. The key risk is that defenders lose visibility, allowing ransomware to operate undetected rather than a direct immediate breach impact.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-02

Editions

Related stories