Agenda Ransomware Group Escalates Attacks with New Multi-Stage Loaders
Red | Attack Report
Download PDFThe Agenda (Qilin) ransomware group has evolved its attacks by using NETXLOADER and SmokeLoader to launch stealthy, multi-stage campaigns. NETXLOADER leverages heavy obfuscation to inject malware directly into memory, evading detection. SmokeLoader follows by downloading additional malicious payloads before deploying the Agenda ransomware to encrypt critical systems. This campaign has targeted the healthcare, technology, financial, and telecom sectors across the U.S., Netherlands, Brazil, India, and the Philippines, posing a severe threat to organizations.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox