Latest / Tech Talks With Kinsoft / Qilin Hits WA's Mount Barker Co-operative
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. I want you
- 0:03to just imagine a really tense hostage negotiation
- 0:06for a second. Okay. Sounds intense. I'm picturing
- 0:08it. Right. So the kidnapper is on the phone and
- 0:11they are demanding this massive ransom. They
- 0:14sound dangerous. They obviously have leverage
- 0:17and they're threatening to basically dismantle
- 0:20your life if you don't wire the funds right that
- 0:23second. Yeah. High pressure. Total panic. Exactly.
- 0:25But then you ask for proof of life. You ask to
- 0:29speak to the hostage. Or maybe you ask for a
- 0:31current photograph holding today's newspaper.
- 0:33Something like that. Standard protocol, right?
- 0:35You need to know it's real. Yeah, but then the
- 0:37kidnapper just goes silent. They hang up. Or,
- 0:39I don't know, maybe they send you a totally blank
- 0:41piece of paper. The entire dynamic of that situation
- 0:44just fractures instantly. Oh, absolutely. Because
- 0:47the psychological weight just shifts completely.
- 0:49Right. You have to stop and ask yourself, like,
- 0:51is this a genuine catastrophe? Or am I just being
- 0:54targeted by some incredibly elaborate, high -stakes
- 0:57bluff? Yeah, you aren't just calculating the
- 0:59cost of the ransom anymore. You are suddenly
- 1:02forced to calculate the actual probability that
- 1:05the threat actor even holds the cards they claim
- 1:07to be holding. It's paralyzing. It really is.
- 1:10It paralyzes decision making, which, I mean,
- 1:13in a crisis scenario, that's highly destructive.
- 1:15And that exact specific paralysis is actually
- 1:18playing out across the Australian digital landscape
- 1:21right now. It is. It's wild to watch. We are
- 1:23looking at this startling cyber extortion spree
- 1:27from... early 2026, and it was orchestrated by
- 1:30the Queelan Ransomware Group. Yeah, Queelan has
- 1:33been incredibly aggressive lately. Totally. So
- 1:35over the course of just a single month, Queelan
- 1:38targeted a quartet of Australian businesses.
- 1:40And for our discussion today, we are going to
- 1:43put one of those victims under the microscope,
- 1:45which is the Mount Barker Cooperative in Western
- 1:47Australia. That's a really good focal point for
- 1:50this. Yeah, because we really need to examine
- 1:52how modern cyber cartels like Quillen are structuring
- 1:57their operations. You know, like why the data
- 1:59they claim to hold is shrouded in so much mystery.
- 2:02And ultimately, what practical steps you and
- 2:05your business need to take to protect yourselves.
- 2:06And Mount Barker Cooperative serves as a perfect
- 2:09lens for this, honestly. It highlights a massive
- 2:12shift in threat actor targeting toward regional
- 2:14supply chains. Right. Getting away from just
- 2:16the giant city corporation. Exactly. And more
- 2:19importantly, it really exposes the somewhat chaotic,
- 2:22decentralized reality of modern ransomware. It
- 2:26kind of shatters that myth of the omnipotent,
- 2:29flawless hacker syndicate. Yeah, they aren't
- 2:31all just typing perfectly in green code in a
- 2:33dark room. Let's actually map out the timeline
- 2:35of this spree because it's interesting. Let's
- 2:37do it. So on January 30th, 2026, Colin goes on
- 2:41this sudden offensive. They hid an electronics
- 2:43retailer, Esperance Communications, out in Western
- 2:46Australia. OK, so starting at West. Right. And
- 2:49then shortly after that, they list another WA
- 2:51business, Esperance Meadowland. Now, with Meadowland,
- 2:54they claimed a very specific haul. They said
- 2:57they got 14 gigabytes of data encompassing over
- 2:5916 ,000 files. That is a very specific flex.
- 3:03It is. And then they break their Western Australian
- 3:05streak just briefly for a target in Queensland.
- 3:08But the real... The centerpiece of this whole
- 3:11campaign, the one we're focusing on, lands on
- 3:14February 11th. Right. The Mount Barker listing.
- 3:16Exactly. That is when Kwilin lists the Mount
- 3:19Barker cooperative on their dark web leak site.
- 3:22And they claim to have exfiltrated 40 gigabytes
- 3:25of internal business data. I mean, 40 gigabytes
- 3:28is a substantial volume of text and documents.
- 3:31It sounds like a lot. Oh, it is. Depending on
- 3:33the density of the files, that could easily be
- 3:35a decade's worth of financial ledgers, member
- 3:37databases, supply chain logistics, employee records,
- 3:40you name it. Really sensitive stuff. Yeah. For
- 3:42a regional food and farm cooperative, that is
- 3:45basically the operational crown jewels. But here
- 3:48is where it gets really interesting. Here's the
- 3:50twist. You navigate via a Tor browser to Quillen's
- 3:55dark web leak portal. to actually verify this
- 3:58claim, right? Because you want to see the proof
- 4:01of life. Exactly. And they boast that the 40
- 4:04gigabytes have been published to the world to
- 4:06see. So you click the directory link to the data
- 4:09and it just throws a 404. Not found error. This
- 4:12is a dead page. Delete dead end. And this wasn't
- 4:14just some isolated glitch for Mount Barker either.
- 4:17Across this entire four target spree, the hackers
- 4:21provided virtually zero hard verifiable evidence
- 4:24that the exfiltration was actually successful.
- 4:27Which is fascinating. From an operational standpoint.
- 4:30It's baffling. It's like a bank robber running
- 4:32out of the vault, waving this completely empty
- 4:34sack and screaming to the police that they took
- 4:37a million dollars. That's a great way to put
- 4:39it. Like, why would a hacker syndicate publicly
- 4:41announce a hack but fail to provide the proof?
- 4:44I struggle to understand the strategic value
- 4:46there. If your whole business model relies on
- 4:48reputational damage and terror, failing to produce
- 4:50the data just destroys your credibility. Well,
- 4:53see, that assumes their primary operational goal
- 4:56is maintaining this pristine, reliable reputation
- 4:59rather than simply generating immediate blinding
- 5:03panic. Oh, interesting. So the panic is the point.
- 5:06Often, yes. We have to look at the psychological
- 5:08warfare of that initial leak site post. When
- 5:11Qualyn lists Mount Barker, automated scrapers
- 5:14pick that up instantly. Right, the threat intelligence
- 5:16feeds. Exactly. Threat intelligence feeds broadcast
- 5:19it. The cybersecurity media starts making calls.
- 5:22The board of directors demands an immediate incident
- 5:24briefing. Even with the 404 error? Even with
- 5:27the 404 error staring them right in the face.
- 5:30The victim organization is instantly plunged
- 5:32into chaos. The uncertainty itself becomes a
- 5:35weapon. Okay, but I'd argue that the uncertainty
- 5:37might actually backfire on the attacker. How
- 5:39so? Well, if the IT team investigates and realizes,
- 5:42hey, no massive data transfer actually occurred,
- 5:45the board might just refuse to pay. They'd call
- 5:48the bluff. That's a fair point. But think about
- 5:51the initial shockwave. The IT team still have
- 5:54to assume a breach until they can definitively
- 5:56prove otherwise. Ah, I see. Which means 24 -7
- 5:59forensic analysis, completely isolating their
- 6:02networks and essentially halting business operations
- 6:04just to prove a negative. Just to prove the data
- 6:07didn't leave. And proving a negative in IT is
- 6:10brutal. Precisely. Proving a negative in a complex
- 6:14network environment takes weeks. During that
- 6:17window of extreme exhaustion and operational
- 6:19downtime, executives might feel pressured to
- 6:23negotiate anyway just to make the public relations
- 6:25nightmare vanish. Regardless of whether the 404
- 6:28error is there or not. Wow. Well, let's actually
- 6:31dig into that 404 error technically for a second,
- 6:34because it points to something fundamentally
- 6:35broken in Quillen's execution. It definitely
- 6:37does. A 404 on a hidden service means the server
- 6:41itself is reachable, but the specific resource
- 6:43just isn't there. It suggests an automated system
- 6:46probably generated the leak page, but the backend
- 6:49payload, the actual data never arrived. Yeah,
- 6:52that points to the architecture of the group.
- 6:53Right. Which brings us to how Quillen is actually
- 6:56structured. They aren't just this cohesive team
- 6:58sitting in a single room somewhere. They operate
- 7:01what's called a ransomware as a service or row
- 7:03S model. Yeah. Radis is essentially the industrialization
- 7:07of cybercrime. Break that down for us. Sure.
- 7:10So the core Killen developers, the guys at the
- 7:12top, they build the sophisticated encryption
- 7:14binaries. They maintain the dark web infrastructure
- 7:17and they manage the extortion negotiation portals.
- 7:21They build the tool. Right. But they outsource
- 7:24the actual network intrusion to independent contractors.
- 7:27The affiliates. Exactly. Known in the ecosystem
- 7:29as affiliates. So the core group takes a percentage
- 7:32of the final ransom and the affiliate keeps the
- 7:36rest. It's literally a franchise model. And according
- 7:39to a November 2025 report from ThreatLocker,
- 7:42this franchise model has allowed Quillen to scale
- 7:45at just a terrifying rate. The numbers are staggering.
- 7:49They really are. They went from claiming 45 victims
- 7:51in 2022 to boasting more than 800 victims in
- 7:542025. Yeah, and you don't hit 800 victims a year
- 7:57without heavy automation. Exactly. So my hypothesis
- 8:00is that the Quillen leak site is hooked into
- 8:03an API. When an affiliate successfully detonates
- 8:06the ransomware inside a target network, the equivalent
- 8:09infrastructure automatically generates a leak
- 8:11page to start that extortion clock. That makes
- 8:13perfect sense. But the core system doesn't actually
- 8:16verify if the affiliate bothered to successfully
- 8:19exfiltrate the data first. I think that API disconnect
- 8:23is a highly probable scenario because in a decentralized
- 8:28RAAS model, quality control is practically non
- 8:32-existent. You get what you get with these affiliates.
- 8:34Yeah, you are mixing highly sophisticated initial
- 8:36access brokers with, frankly, impatient amateurs.
- 8:40Right, someone who just bought a login and wants
- 8:42a quick payout. Exactly. An affiliate might breach
- 8:45Mount Barker's perimeter, stumble around a bit,
- 8:47trigger an endpoint detection and response alert,
- 8:50panic, and then immediately execute the encryption
- 8:53binary before they even establish a stable exfiltration
- 8:55channel. So they lock the doors before stealing
- 8:58the furniture. Yeah. The ransomware phone's home
- 9:00to Creeland saying, hey, target encrypted. The
- 9:02API auto -publishes the victim's name and an
- 9:05estimated data size based on the network, but
- 9:07the actual data repository on the dark web remains
- 9:10empty. Hence, the 404. Or, you know, considering
- 9:14we're talking about 40 gigabytes here, they might
- 9:17have tried to push that volume out of the network,
- 9:19hit a bandwidth bottleneck, and the connection
- 9:22just timed out. Also very possible. Moving 40
- 9:25gigs quietly without tripping a network traffic
- 9:27anomaly alert isn't exactly trivial for a sloppy
- 9:31affiliate. No, it's not. And that variability
- 9:33in affiliate skill is really what makes defending
- 9:36against a rice threat. So unpredictable. The
- 9:39left hand doesn't know what the right hand is
- 9:41doing. Precisely. The core cooling operators
- 9:43might be sitting there expecting a clean double
- 9:46extortion play, stealing the data and locking
- 9:48the machines. But the affiliate on the ground
- 9:51just botched the heist and ran out the door empty
- 9:54handed. Leaving the core group to just bluff
- 9:56their way through the negotiation with a 404
- 9:58page. Exactly. But. We really shouldn't let the
- 10:03sloppy data exfiltration lull us into a false
- 10:06sense of security here. Oh, absolutely not. Because
- 10:08while their backend data handling might be throwing
- 10:10404s, the methodology they use to actually penetrate
- 10:13and occupy these networks is incredibly persistent.
- 10:17Let's look at the timeline of an intrusion for
- 10:18a minute. It's eye -opening. The ThreatLocker
- 10:21report highlighted a statistic that fundamentally
- 10:23changes how we need to view these attacks. They
- 10:26found that Quillen affiliates have an average
- 10:28dwell time. Of 19 days. 19 days. Let that sink
- 10:33in. They are inside a network for nearly three
- 10:36weeks before the encryption payload is ever detonated.
- 10:39That is wild. It completely shatters that legacy
- 10:42idea of a cyber attack being this quick smash
- 10:45and grab operation. It really does. Because if
- 10:48they are maintaining persistence for 19 days,
- 10:50they aren't just blasting a malicious executable
- 10:52and hoping for the best. They are actively evading
- 10:55detection. Very carefully evading it. My assumption
- 10:58is. They're using what we call living off the
- 11:01land techniques, right? That's exactly what they
- 11:02do. So instead of bringing in noisy malware that
- 11:05a standard antivirus would immediately flag,
- 11:08they compromise an administrator's credentials.
- 11:10And then they just use the network's own native
- 11:12legitimate tools like PowerShell or Windows Management
- 11:15instrumentation to move laterally. Yeah. That
- 11:19is exactly how they maintain that stealth profile.
- 11:21They co -op the very administration tools that
- 11:24your own IT department uses every single day.
- 11:28Which makes them look like normal employees to
- 11:30the system. Right. And during those 19 days,
- 11:32the affiliate is conducting rigorous enumeration
- 11:35and discovery. Boking around, seeing what's what.
- 11:38Methodically mapping the Active Directory environment.
- 11:41They locate the domain controllers to escalate
- 11:44their privileges to domain admin. They identify
- 11:47exactly where the critical databases for operations
- 11:50and finance are housed. They are basically reading
- 11:54your playbook while you sleep. But wait, if I'm
- 11:57running a modern security operations center,
- 11:58how does an attacker sit in my environment for
- 12:0119 days querying active directory and scanning
- 12:03subnets without lighting up my telemetry like
- 12:05a Christmas tree? Well, often they just disable
- 12:08or blind the telemetry. Seriously? Yeah. If they
- 12:11compromise an account with sufficient privileges
- 12:13early on, their first move is usually to tamper
- 12:16with the EDR agents on the endpoints. They are
- 12:19essentially turning off the security cameras
- 12:21before they start moving the heavy equipment.
- 12:23That is terrifying. It is. But you know, the
- 12:26most critical phase of that entire 19 -day dwell
- 12:28time isn't just finding the data to steal, it's
- 12:31hunting down the backups. Ah, of course. Because
- 12:33backups are the ultimate leverage breaker. 100%.
- 12:36If an affiliate encrypts the Mount Barker Cooperative
- 12:39servers, but the IT director can just press a
- 12:42button and spin up a clean snapshot from yesterday,
- 12:44the ransom demand is totally toothless. The affiliate
- 12:48knows this. So they spend those two weeks methodically
- 12:51seeking out the backup servers. They delete volume
- 12:53sh - shadow copies and they attempt to corrupt
- 12:56offsite storage credentials. They want to make
- 12:59sure you have no safety net. Exactly. They want
- 13:01to ensure that when they finally execute that
- 13:03Qualen binary on day 19, the victim is totally
- 13:06paralyzed. Which honestly makes the 404 error
- 13:09we discussed earlier even more complex. An affiliate
- 13:12might successfully spend 19 days crippling your
- 13:15backups and deploying the encryptor perfectly,
- 13:17but then they just fail at the data exfiltration
- 13:20piece. Right. The company is still paralyzed,
- 13:22even if the data wasn't actually stolen. Exactly.
- 13:25And this brings us to the targeting strategy,
- 13:27I think, because if these affiliates are spending
- 13:30three weeks methodically dismantling a network,
- 13:33they are putting in significant effort. Why aim
- 13:37that level of effort at a regional food and farm
- 13:40cooperative in Western Australia? Well, it is
- 13:43a very ruthless calculation of the risk to reward
- 13:46ratio. How so? Regional cooperatives operate
- 13:49at this critical intersection of physical supply
- 13:51chains and digital logistics. They manage payments
- 13:55for local farmers. They coordinate freight. They
- 13:57handle vast amounts of member data. And they
- 14:00often interface with physical industrial control
- 14:02systems. So they have incredibly high uptime
- 14:05requirements. Massive uptime requirements. If
- 14:07Mount Barker Cooperative goes offline, it's not
- 14:09just a digital inconvenience. You know, it's
- 14:12real world impact. Exactly. Local agriculture
- 14:15logistics grind to a halt. Produce physically
- 14:17doesn't move. Payments freeze. The cascading
- 14:20effect on the regional economy is immediate and
- 14:23severe. And high criticality translates directly
- 14:25to high extortion leverage for the hackers. Precisely.
- 14:29However, historically, these regional hubs do
- 14:32not possess the massive enterprise tier cybersecurity
- 14:35budgets of, say, a tier one bank in Sydney. They
- 14:38might have leaner I .T. teams, maybe. managing
- 14:41sprawling legacy infrastructure. Yes. So for
- 14:45Array Esiliot, a regional cooperative represents
- 14:47a target that will experience immense immediate
- 14:50pain from downtime, but they may lack the layered
- 14:53zero trust architecture needed to stop a determined
- 14:56intruder from escalating privileges. It's basically
- 14:59the perfect storm of high leverage and potentially
- 15:01softer perimeters. It unfortunately is. So let's
- 15:04talk solutions. How do we disrupt this attack
- 15:06chain? Because we know the adversary's playbook
- 15:09now, right? We have opportunistic access, a 19
- 15:12-day lateral movement phase, targeting of backups,
- 15:15and a delayed payload detonation. Right. The
- 15:17blueprint is clear. So if you are operating a
- 15:19business outside a major metropolitan center
- 15:21or running any organization where downtime is
- 15:23catastrophic, how do you actually defend against
- 15:25this decentralized Reyes threat? You have to
- 15:28engineer your defenses to exploit their specific
- 15:30operational requirements. Okay. Where do we start?
- 15:33The first countermeasure tackles their initial
- 15:35access vectors. Most of these affiliates purchase
- 15:37compromised session tokens or utilize credential
- 15:40stuffing to breach the perimeter. So just standard
- 15:43passwords aren't enough? Not even close. And
- 15:46honestly, standard multi -factor authentication
- 15:48is no longer sufficient either. Really? Why is
- 15:51that? Because attackers routinely bypass it using
- 15:54MFA fatigue attacks. That's where they bombard
- 15:56a user with push notification approval requests
- 15:59until the user gets annoyed and accidentally
- 16:01clicks accept. Or they use adversary in the middle
- 16:05phishing proxies to steal the session token after
- 16:07the user authenticates. Oh, wow. So what's the
- 16:10move then? The move is toward phishing -resistant
- 16:13MFA, like FIDO2 hardware security keys. Okay,
- 16:16the physical keys you plug in. Exactly. With
- 16:19those, the authentication is cryptographically
- 16:21bound to the physical device in the specific
- 16:23login domain. Even if an affiliate buys a stolen
- 16:26password or intercepts a session token, the hardware
- 16:29key requirement stops the initial intrusion cold.
- 16:32Because they physically don't have the key in
- 16:34their hands in Russia or wherever they are? Precisely.
- 16:37That secures the perimeter. But... As always
- 16:41in cybersecurity, you must assume breach. Right.
- 16:44Assume they get it anyway. Yes. And this is where
- 16:47active threat hunting and network segmentation
- 16:50come into play to disrupt that 19 -day dwell
- 16:53time. Because if an attacker does bypass the
- 16:56perimeter, they rely on a flat network architecture
- 16:59to move laterally. Right. Like moving from a
- 17:02compromised receptionist's workstation straight
- 17:05over to a critical financial database. Exactly.
- 17:07So by segmenting the network, putting strict
- 17:10access controls and firewalls between different
- 17:12departments and server clusters, you force the
- 17:15attacker to make noise. You put hurdles in their
- 17:17way. Right. Every time they try to cross a boundary,
- 17:20they generate an anomaly. If you have a system
- 17:22actively monitoring for anomalous lateral movement
- 17:24or unexpected Active Directory queries, you catch
- 17:27them on day two of their discovery phase, long
- 17:29before they find the backups. And speaking of
- 17:32those backups, they must be genuinely immutable,
- 17:34right? We hear immutables thrown around as a
- 17:36buzzword a lot lately. It is a buzzword, but
- 17:39it's critical. Let's define what actually saves
- 17:41a business here, because it's not just having
- 17:44a backup on a different server down the hall.
- 17:46No, definitely not. An immutable backup is written
- 17:48in a write -once -read -many state. Okay. Once
- 17:51the data is committed to that storage, it cannot
- 17:53be altered, encrypted, or deleted by anyone,
- 17:56not even a domain administrator. And it stays
- 17:59that way for a predetermined retention period.
- 18:02So the ransomware literally can't touch it. Right.
- 18:05Furthermore, the authentication plane for the
- 18:07backup infrastructure must be completely isolated
- 18:10from your primary Active Directory environment.
- 18:12Ah, so they can't use the stolen credentials
- 18:15to log into the backup server. Exactly. If the
- 18:18Quillen affiliate compromises your domain admin
- 18:20credentials, those credentials should be utterly
- 18:24useless for accessing the backup storage. That
- 18:26makes total sense. If you implement isolated
- 18:29immutable storage, you basically neutralize the
- 18:31entire Quillen business model. You take away
- 18:34their power. Yeah, even if they sit in the network
- 18:36for 19 days, even if they deploy the encryptor
- 18:39flawlessly, you just refuse the negotiation.
- 18:42You wipe the environment and restore operations
- 18:44from those immutable snapshots. The threat of
- 18:46a 40 -gigabyte ransom shifts from a company -ending
- 18:50disaster to just a contained incident response
- 18:53exercise. You strip away their leverage and,
- 18:55by extension, their psychological terror. Exactly.
- 18:58This whole examination of the Quillen attacks
- 19:01really highlights the shifting mechanics of cyber
- 19:03warfare. I mean, we are dealing with an industrialized
- 19:07RIAS ecosystem scaling to hundreds of victims,
- 19:09executing these patient - day infiltrations and
- 19:13aggressively targeting the vital but often under
- 19:16defended regional supply chains like the Mount
- 19:18Barker Cooperative. It's a very sophisticated
- 19:20threat landscape. It is. And yet the operational
- 19:23friction of this gig economy model frequently
- 19:25results in chaotic execution, leaving victims
- 19:28staring at 404 errors while trying to decipher
- 19:31if they've actually lost their data or not. Yeah.
- 19:33But, you know, before we conclude, there is a
- 19:35natural and frankly disturbing evolution of this
- 19:38missing data tactic that. organizations really
- 19:41must prepare for. Oh, what's coming next? Well,
- 19:44we analyzed how a group like Quillen generates
- 19:47panic simply by listing a company's name on a
- 19:50leak site, even without providing the stolen
- 19:53data, right? Yeah, the bluff. The next phase
- 19:56is the weaponization of generative AI. Wait,
- 19:58like synthesizing the proof? Exactly. In the
- 20:01near future, an attacker won't need to spend
- 20:0419 days carefully exfiltrating 40 gigabytes of
- 20:07authentic data. They will just breach the perimeter,
- 20:11scrape a few public documents, feed them into
- 20:14a large language model, and instantly generate
- 20:16hundreds of highly convincing, completely fabricated
- 20:20internal records. Like doctored financial ledgers,
- 20:23falsified board minutes, manufactured HR scandals.
- 20:26Exactly. They will use this synthetic data to
- 20:29extort companies who were never meaningfully
- 20:31breached in the first place. If a 404 error creates
- 20:34chaos today, imagine a leak site filled with
- 20:36hyper -realistic, AI -generated corporate fabrications.
- 20:40It will be devastating. That is the ultimate
- 20:43evolution of the hostage bluff. They don't just
- 20:44pretend to have the hostage. They use deepfakes
- 20:46to put the hostage on the phone. Precisely. It's
- 20:49coming. Man, that is a chilling thought. To ensure
- 20:52your organization is equipped to navigate these
- 20:54complex, evolving threats, whether it's an advanced
- 20:57RAIS affiliate or a synthetic extortion campaign,
- 21:00you need resilient, layered architecture. You
- 21:03really do. So visit www .kinsoft .com .au to
- 21:07discuss your security and IT needs. You must
- 21:10engineer your environment so that when the threat
- 21:12actors come testing your perimeter, you are the
- 21:14one holding the leverage. Thank you for joining
- 21:16our discussion today. stay vigilant assume breach
- 21:19and isolate your backups secure your environments
- 21:22everyone