Latest / Tech Talks With Kinsoft / Qilin's WA Spree – Esperance Metaland
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Welcome to
- 0:02Tech Talks with Kinsoft. You know, it's funny,
- 0:04we both just jumped right on that exact intro.
- 0:07Yeah, well, we're definitely eager to get into
- 0:09today's topic. We really are. Because, you know,
- 0:12usually when you picture a business falling victim
- 0:14to a cyber attack, you imagine this massive,
- 0:18sudden... Digital explosion. Right. Like alarms
- 0:21ringing in an IT control room. Exactly. Screens
- 0:23flashing red and the entire company network just
- 0:26locks down in an instant. Brutal chaos. Total
- 0:29chaos. But right now we're looking at this sudden
- 0:32wave of cyber extortion that's sweeping through
- 0:34regional Australian businesses in early 2026.
- 0:38And the reality is it feels. completely different
- 0:42it's much quieter yeah imagine waking up you
- 0:44walk into your kitchen and you find a typed menacing
- 0:47ransom note just sitting right there on your
- 0:49table oh wow yeah that's a terrifying image right
- 0:53and the note claims your house has been entirely
- 0:55cleared out of all your valuables it's really
- 0:57visceral terrifying feeling oh absolutely it
- 1:00creates this immediate sense of panic your first
- 1:03instinct is just that your entire life has been
- 1:05turned upside down but then you start looking
- 1:08around your house and uh Your television is still
- 1:12matted on the wall. Right. Your jewelry box on
- 1:14the dresser, it hasn't been touched. Your laptop
- 1:17is sitting exactly where you left it. So nothing's
- 1:19actually missing. Exactly. You're holding this
- 1:21terrifying note demanding money, but you can't
- 1:24actually figure out if a single thing was stolen.
- 1:26And that bizarre unsettling gap between a massive
- 1:30threat and the reality on the ground. That's
- 1:33the core of our conversation today for you listeners.
- 1:36It really is, because we are looking closely
- 1:38at a string of ransomware attacks targeting Western
- 1:40Australia and Queensland. And this is driven
- 1:43by a group called Quillen. Right. Yes. Queensland.
- 1:45And what stands out immediately is the distinct
- 1:48regional focus. I mean, we aren't talking about
- 1:50multinational banks headquartered in Sydney or
- 1:53Melbourne here. Right. It's a concentrated cluster
- 1:55in regional areas. Exactly. Out of four victims
- 1:57claimed in just under a month, starting in late
- 2:00January 2026, three of them were in Western Australia.
- 2:04Yeah. You had Esperance Communications at the
- 2:07end of January, Mount Barker Cooperative in early
- 2:10February, and then a victim over in Queensland.
- 2:13But the incident that perfectly captures this
- 2:16whole, I guess I call it a phantom ransom note
- 2:19vibe, is what happened to Esperance Meadowland.
- 2:22Oh, absolutely. Esperance Meadowland is the perfect
- 2:24example. So on the 21st of February, 2026, this
- 2:28regional WA business suddenly found its name
- 2:31plastered across Quillen's dark web leak site.
- 2:34And they didn't just casually mention them, did
- 2:35they? No, not at all. The group strutted around
- 2:38making very specific, very quantifiable claims.
- 2:42They stated they had successfully exfiltrated
- 2:4414 gigabytes of sensitive data. Wow. Yeah, comprising
- 2:48over 16 ,000 individual files. Okay, I want to
- 2:51pause on that word for a second, exfiltrated.
- 2:54Because it sounds like a spy movie term. It does
- 2:56sound very dramatic. But in plain English, we're
- 2:58basically talking about the act of smuggling
- 3:00data out of the building. Like the hackers are
- 3:01claiming they didn't just lock the files up.
- 3:03Right. They made copies. They made copies and
- 3:05hauled those copies out the back door to their
- 3:07own servers. And, you know, 14 gigabytes of purely
- 3:11sensitive company data is massive. It's a huge
- 3:15amount of text. Yeah, we aren't talking about
- 3:17a few heavy video files here. We're talking about
- 3:19text documents, spreadsheets, tax records, customer
- 3:22details. That is the digital equivalent of a
- 3:26massive, heavy, physical filing cabinet, absolutely
- 3:30stuffed to the brim with paper. That's a great
- 3:33way to picture it. So if they really managed
- 3:35to haul this giant cabinet out of Esperance Meadowlands
- 3:39Network, where's the proof? Like, have they shown
- 3:42any of it? See, that is the most critical detail
- 3:45of this entire incident. The answer is no. Quillen
- 3:48provided absolutely zero hard evidence to verify
- 3:51that the breach actually contained what they
- 3:53claimed. Wait, really? Nothing at all? Nothing.
- 3:56There were no sample files leaked. There were
- 3:58no screenshots of sensitive directories. It was
- 4:00literally just a text post on a hidden forum
- 4:02demanding a ransom. So they're out there bragging
- 4:05about the heist of the century, but they aren't
- 4:07holding up any of the cash. Exactly. Which puts
- 4:10the victim in an incredibly complex situation.
- 4:13You have to understand the genuine uncertainty
- 4:14this creates for, say, an incident response team
- 4:18or a regional business owner sitting in their
- 4:21office in Esperance. Yeah. I mean, you see this
- 4:23post and you're forced to figure out if your
- 4:26most sensitive intellectual property and employee
- 4:28records are actually in the hands of criminals.
- 4:31Right. Or if the hackers just scraped some public
- 4:33information off your company website and packaged
- 4:35it up to look terrifying. When there is no proof,
- 4:38you're essentially shadowboxing. Shadowboxing.
- 4:41That's a good way to put it. What's wild is that
- 4:43this lack of proof at Esperance Meadowland, it
- 4:46isn't just a one -off mistake by the hackers.
- 4:48No, not at all. It seems to be part of a really
- 4:51bizarre operational pattern for Kylan right now.
- 4:53Yeah. The Mount Barker cooperative case is particularly
- 4:56illustrative of this pattern. So on February
- 4:5911th, an affiliate of the Kylan group listed
- 5:01them on the leak site. Okay. And in that instance,
- 5:04they actually claimed to have published the stolen
- 5:06data. They literally said, here is 40 gigabytes
- 5:09of your data. Go look at it. Oh, so they'd supposedly
- 5:12provided the proof that time. Well, they provided
- 5:14a link. But when security researchers and journalists
- 5:17went to click that dark web link to view or download
- 5:21the data, it just returned a standard web error.
- 5:24Let me guess. A 404. Not found. A 404 error on
- 5:29a dark web extortion site. I mean, that is almost
- 5:32comical. It really is. And then there's the unnamed
- 5:34Queensland victim from February 22nd. The dark
- 5:37web listing for them doesn't even have a file
- 5:40count or a date. Yeah. It's just a blank threat.
- 5:43Which brings us to the psychological warfare
- 5:45aspect of modern cyber extortion. Okay. Unpack
- 5:48that for us. Well, we tend to view ransomware
- 5:51groups purely as technical threats, right? We
- 5:53imagine brilliant coders furiously typing in
- 5:56dark rooms. Hackers in hoodies. Exactly. But
- 5:59at their core, they are extortionists. And extortion
- 6:02relies entirely on fear and perceived leverage.
- 6:06They want you to panic. But wait, I have to ask
- 6:08this from the perspective of a business owner.
- 6:10If I see my company name on that site and I click
- 6:13the link and get a 404 error, my first instinct
- 6:16is going to be relief. Oh, absolutely. I'm going
- 6:18to assume they're bluffing or their site is broken
- 6:20and maybe I can just ignore it. Can I safely
- 6:22make that assumption? You absolutely cannot assume
- 6:25a 404 error means the data doesn't exist. Really?
- 6:28Why not? Because dark web infrastructure, specifically
- 6:31the Tor network that these leak sites run on.
- 6:34is notoriously unstable. It might just be misconfigured
- 6:38server settings on their end, or, and this is
- 6:41important, they might be holding the data back
- 6:44intentionally to slowly build pressure. Like
- 6:47a drip feed of anxiety. Exactly. A drip feed
- 6:49to see if you'll crack and pay up before they
- 6:52even have to prove anything. Wow. Okay, so how
- 6:55do you avoid completely panicking while still
- 6:58taking the threat seriously? Because if the dark
- 7:01web site is useless for figuring out the truth,
- 7:03where do you look? You don't react to the external
- 7:06dark web posts. You react to your own internal
- 7:08data logs. Internal logs. Yes. This requires
- 7:11a calm, systematic assessment. You look at your
- 7:14network traffic from the dates in question. Do
- 7:16your firewalls show a massive 40 gigabyte outbound
- 7:19transfer to an unknown server? Because 40 gigs
- 7:22is hard to hide. Very hard. Do you see unauthorized
- 7:25access to your file servers? If your internal
- 7:28logs show absolutely no massive data exfiltration
- 7:31and the hackers are just throwing up 404 errors,
- 7:35your risk assessment fundamentally changes. So
- 7:38you navigate that gray area with internal evidence,
- 7:41not external fear. Exactly right. OK, so that
- 7:44explains the psychology of the victim. But I'm
- 7:46still stuck on the sloppiness of the attackers.
- 7:48Yeah, it's interesting. Like, why are we seeing
- 7:51broken links, missing file counts and empty threats?
- 7:54If these are supposed to be elite hackers, why
- 7:56do they seem so disorganized? To understand that,
- 7:59we need to look under the hood at the business
- 8:01model powering Qualen. They operate on a model
- 8:04known as ransomware as a service or RAS. Ransomware
- 8:07as a service. So it's like a fast food franchise
- 8:09model, but for cybercrime. That is a perfect
- 8:12analogy. The core Quillen developers, the corporate
- 8:15headquarters in this scenario, aren't necessarily
- 8:17the ones breaking into Esperance Metal Land.
- 8:20Right. Quillen Corporate develops the branding.
- 8:22They maintain the dark web leak site. And they
- 8:25write the highly sophisticated ransomware software
- 8:27itself. And then they rent that software out
- 8:30to local franchisees, which I think the industry
- 8:33calls affiliates. Yes, affiliates. And these
- 8:36affiliates are the ones actually doing the dirty
- 8:37work of breaking into the regional businesses
- 8:40network. and deploying the software that's right
- 8:43And if they manage to extort money from the victim,
- 8:46they split the profits with the Quillen headquarters.
- 8:48That is wild. And this franchise model is terrifyingly
- 8:52scalable because it lowers the barrier to entry
- 8:55so much. We have data from a November 2025 Threat
- 8:59Locker report showing just how fast this specific
- 9:02engine is moving. What did the report say? Well,
- 9:05in 2022, Quillen claimed just 45 victims. 2025,
- 9:10they were boasting more than 800 victims globally.
- 9:12Over 800 victims. That is an exponential explosion.
- 9:15Yeah. But, you know, going back to the fast food
- 9:17analogy, when you have a franchise scaling that
- 9:19quickly, your quality control is going to completely
- 9:22fall apart. Precisely. Corporate HQ might have
- 9:24a brilliant recipe for the malware, but the local
- 9:27franchisee might just be an amateur who is incredibly
- 9:30sloppy at their job. Which is an active debate
- 9:32in the cybersecurity community right now regarding
- 9:34Coil and sophistication. Because of the franchise
- 9:37model, the skill level of the attacker varies
- 9:40wildly depending on which affiliate targets you.
- 9:42Makes sense. Some analysts suspect that certain
- 9:45Quail affiliates aren't executing complex, elite
- 9:48hacks at all. Instead, they are just using automated
- 9:51scanning tools to hunt for company databases
- 9:54that were accidentally left open to the public
- 9:56internet. Oh, wow. So they aren't picking locks.
- 9:59No. They were just walking down the street checking
- 10:01for unlocked front doors. Exactly. They find
- 10:04an open database, download the contents, and
- 10:06demand a ransom. Which would absolutely explain
- 10:09the missing files and the broken dark web links.
- 10:11Yeah. If the affiliate is just an amateur who
- 10:14bought access to Qualent's platform, they might
- 10:16mess up the data upload or misconfigure the hidden
- 10:19server. Or just straight up lie about how much
- 10:22data they grabbed to try and secure a quick payday.
- 10:24Right. However, we cannot underestimate the core...
- 10:27technology. While the individual affiliate might
- 10:30be a sloppy amateur, the Kwilan headquarters
- 10:33provides them with a genuinely potent weapon.
- 10:36So the malware itself is still highly dangerous.
- 10:39Extremely. The evidence shows that the Kwilin
- 10:42ransomware software utilizes highly effective
- 10:44methods to embed itself in a network. And there
- 10:48is one metric from the ThreatLocker report regarding
- 10:50Kwilin that every single business leader needs
- 10:53to commit to memory. Okay, what is it? 19 days.
- 10:5719 days. What happens for 19 days? That is their
- 11:00historical average dwell time. Dwell time? Yeah.
- 11:04It means the affiliate... it breaks into the
- 11:06network, establishes a hidden communication channel
- 11:08with their own servers, and then just lurks inside
- 11:11the victim's network completely undetected for
- 11:14almost three weeks before they actually trigger
- 11:16the ransomware and lock everything down. Almost
- 11:18three weeks. I mean, so they aren't just doing
- 11:20a smash and grab. What are they doing inside
- 11:23the network for all that time? They are performing
- 11:25what we call lateral movement and privilege escalation.
- 11:29OK, pretend I have no idea what those terms mean.
- 11:31How does that work, like, mechanically? Well,
- 11:34think of it like a physical break -in. The attacker
- 11:35doesn't start in the vault. Okay. They start
- 11:37by breaking a window in the lobby. Maybe by compromising
- 11:40a receptionist's computer. From there, they move
- 11:43laterally looking for the janitor's keys. Once
- 11:46they have those, they access the elevator. Then
- 11:49they try to escalate their privileges to get
- 11:51the CEO's master key. Ah, I see. In a digital
- 11:55sense, they are moving from a low -level workstation
- 11:57to the central servers, seeking administrative
- 12:00passwords. They use those 19 days to map the
- 12:03network, locate the most sensitive data at Exfiltrate.
- 12:07Read the company's financial statements to figure
- 12:10out how much ransom they can afford to pay. That's
- 12:13creepy. And crucially, they hunt down the company's
- 12:15backups to destroy them. That is horrifying.
- 12:18It's literally like a horror movie where the
- 12:20call is coming from inside the house and they've
- 12:22been living in your attic for weeks. It really
- 12:24is. But wait, if they are stumbling around in
- 12:27the dark. digital hallways of a business for
- 12:3019 days? Yeah. Isn't that actually a massive
- 12:32vulnerability for them? How do you mean? Well,
- 12:35doesn't that long dwell time mean we have a three
- 12:37week head start to catch them before they steal
- 12:39the data or lock the screens? You've hit on the
- 12:42exact paradigm shift that modern network defense
- 12:44requires. A 19 -day dwell time is an attacker's
- 12:49greatest vulnerability. Yeah. The hackers are
- 12:51entirely reliant on remaining undetected while
- 12:55they stage their attack. If you catch them on
- 12:57day three or day 12, there is no ransomware deployment.
- 13:01There is no dark web extortion post. It is a
- 13:0319 -day window of opportunity for the defender.
- 13:07So let's talk about how to actually use that
- 13:09window. We know they're targeting regional businesses
- 13:11in WA and Queensland. We know they're using this
- 13:13franchise model looking for easy wins. Let's
- 13:16use the Esperance Meadowlands situation as a
- 13:18lens here. Okay. How do regional businesses turn
- 13:22the tables? What are the practical mechanical
- 13:24defenses that break this attack chain? Step one
- 13:27is shutting down the initial access point. And
- 13:30that almost universally means implementing multi
- 13:32-factor authentication or MFA everywhere. Yeah,
- 13:35we hear about MFA constantly, you know, getting
- 13:37a text code or using an app on your phone. But
- 13:40how does that specifically stop a Quillen affiliate?
- 13:42You mentioned the unlocked front door earlier.
- 13:45Imagine an amateur affiliate goes onto an underground
- 13:48forum and buys a stolen password belonging to
- 13:51one of your employees. Right. If you don't have
- 13:53MFA, that stolen password is the master key to
- 13:56your front door. The attacker logs in and the
- 13:5919 -day clock starts. Right. But if MFA is active,
- 14:02the attacker enters the password and the system
- 14:05prompts them for a fingerprint or a code sent
- 14:07to the employee's phone. And the attacker doesn't
- 14:09have the phone. Exactly. The attack chain breaks
- 14:12right there. MFA neutralizes the value of stolen
- 14:15passwords, keeping the lazy franchisees out.
- 14:18Okay, so the deadbolt is installed. But what
- 14:21if a more skilled affiliate slips past the MFA?
- 14:23Maybe they find a flaw in the software itself.
- 14:26What is step two to cache them during those 19
- 14:29days? Step two is active monitoring. You need
- 14:33visibility into your network to catch them while
- 14:35they are lurking. Remember, when they are moving
- 14:37laterally and escalating privileges, they are
- 14:40doing things normal employees don't do. So how
- 14:43do you spot that? You use tools like Endpoint
- 14:45Detection and Response or EDR. EDR platforms
- 14:49don't just scan for known bad viruses. They look
- 14:52for abnormal behavior. Like what? For example,
- 14:55if an accountant's computer, which normally just
- 14:57opens spreadsheets, suddenly attempts to access
- 15:00the central HR server at 3 .0 AM and run a complex
- 15:04administrative command to copy 16 ,000 files,
- 15:07the EDR system flags it instantly. Oh, wow. It's
- 15:11essentially installing highly sensitive motion
- 15:14sensors in the digital hallways of your business.
- 15:16That's a perfect way to put it. If someone is
- 15:18walking where they shouldn't be in the middle
- 15:20of the night, the alarms go off. Exactly. Now,
- 15:22step three is your ultimate fail -safe, backups.
- 15:25But not just any backups. Immutable backups.
- 15:29Immutable, that's a term that gets thrown around
- 15:30a lot in tech circles. Yeah. What does that actually
- 15:33mean mechanically in the context of a ransomware
- 15:35attack? Immutable means read -only and unchangeable.
- 15:38Let's say your monitoring fails, the attacker
- 15:40goes unnoticed for the full 19 days, and they
- 15:43finally trigger the Quillen ransomware to lock
- 15:45all your files. Worst case scenario. Right. The
- 15:48attacker then tries to encrypt or delete your
- 15:51backups, so you are forced to pay them. An immutable
- 15:55backup acts like a physical drop vault. Your
- 15:58system can put data into the vault, but neither
- 16:00an employee, an administrator, nor a hacker can
- 16:04alter or delete the data inside it until a set
- 16:06amount of time has passed. Oh, I see. The ransomware
- 16:09tries to encrypt the backup, and the vault simply
- 16:12rejects the command. That is brilliant. It completely
- 16:15removes the attacker's leverage. You don't have
- 16:17to negotiate or pay to decrypt your systems.
- 16:20You just wipe the infected computers and restore
- 16:23everything from yesterday's unchangeable backup.
- 16:25You ensure the business can continue to operate.
- 16:27Which brings us to the final piece of the defense
- 16:29puzzle. Incident response, or IR. Having an IR
- 16:34plan seems like it addresses the psychological
- 16:36side of this whole ordeal we talked about earlier.
- 16:39It does. Having a comprehensive incident response
- 16:41plan is what prevents the absolute panic we discussed
- 16:44at the very beginning of the show. An IR plan
- 16:46dictates exactly who to call, how to isolate
- 16:49infected machines to stop the spread, and crucially,
- 16:53how to calmly verify the dark web claims using
- 16:56internal logs rather than paying ransoms out
- 16:58of pure terror. It is the difference between
- 17:01a controlled business interruption and an existential
- 17:04corporate crisis. It's the difference between
- 17:06seeing that terrifying ransom note on your kitchen
- 17:08table and screaming versus calmly pulling up
- 17:11your security camera footage to verify if anyone
- 17:14actually came inside. Exactly. And Esperance
- 17:16Meadowlands' situation is a masterclass in why
- 17:19this level of preparation matters. When a regional
- 17:22business is targeted, the geographical distance
- 17:24from major tech hubs like Sydney doesn't afford
- 17:27them a lower standard of security. No, definitely
- 17:29not. The threat actors certainly aren't discriminating
- 17:32by postcode. They're discriminating by vulnerability.
- 17:35They really aren't. And that's what makes this
- 17:372026 spree so eye -opening. For you listening
- 17:40at home, we've traced the path of these targeted
- 17:43attacks hitting regional WA in Queensland. Yeah.
- 17:46Zeroing in on those massive yet unverified claims
- 17:49of stolen data. We looked under the hood at the
- 17:52messy reality of the ransomware as a service
- 17:54model. where highly potent malware is wielded
- 17:57by affiliates with varying levels of competence,
- 17:59resulting in bizarre 404 errors and phantom data.
- 18:04It's a strange landscape. It is. And most importantly,
- 18:07we mapped out how to use that 19 -day dwell time
- 18:10to your advantage, locking the doors with MFA,
- 18:13installing motion sensors with EDR, maintaining
- 18:16immutable backups, and keeping a cool head with
- 18:19an incident response plan. Which leaves us with
- 18:21a final provocative thought to consider. Oh,
- 18:24lay it on us. We've talked extensively about
- 18:26the psychological impact of unverified claims
- 18:28and broken dark web links. As these ransomware
- 18:32groups continue to scale, boasting hundreds or
- 18:34even thousands of victims a year, what if the
- 18:36future of cybercrime isn't about actually stealing
- 18:39data at all? Wait, what do you mean? Think about
- 18:41the effort it takes to maintain that 19 -day
- 18:43dwell time without getting caught. If hackers
- 18:45know they can cause immense operational panic,
- 18:48trigger massive reputational damage, and extort
- 18:50millions of dollars simply by generating a fake
- 18:53dark web post and a 404 error, will they even
- 18:56bother writing real complex ransomware code in
- 18:59the future? If the illusion of a breach pays
- 19:01just as well as the technical execution of one,
- 19:04the entire landscape of cyber threats could shift
- 19:06away from software exploitation entirely and
- 19:09move toward pure psychological manipulation,
- 19:12extortion without the malware. That is a wild
- 19:15concept. Yeah. So the next time you find a terrifying
- 19:18ransom note on your kitchen table, the real test
- 19:20isn't just figuring out if anything was stolen.
- 19:23The real test is having the systems and monitoring
- 19:25in place so you never have to guess in the first
- 19:27place. To make sure your business doesn't end
- 19:29up as a target on a dark web leak site, visit
- 19:31www .kinsoft .com .au today to discuss your security
- 19:35and IT needs.