VORANT. Threat Intelligence Research Sign in Create a free account

Qilin ransomware claims Onsemi breach

high threat manufacturingtechnology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Qilin ransomware group lists semiconductor manufacturer Onsemi as a victim, claiming compromise of employee and user credentials.

Ransomware.live has indexed a Qilin ransomware group claim against Onsemi (ON Semiconductor), a major semiconductor manufacturer. The listing cites compromise of 193 employees, 897 users, and 78 third-party employee credentials, alongside enumeration of the victim's external attack surface (170 items) and DNS records. The entry appears to be a leak-site posting typical of ransomware extortion operations, providing a leak screenshot as proof of compromise.

No technical details on the initial access vector, exploited vulnerabilities, or specific malware used in the intrusion are provided in this listing. The data suggests credential compromise may have played a role, potentially involving infostealer-sourced credentials as referenced by the sponsoring vendor's tooling. Defenders in the semiconductor and broader manufacturing/technology sector should treat this as a reminder to monitor for Qilin ransomware group activity, validate credential hygiene, and check for exposure of employee credentials via infostealer logs.

As this is a leak-site listing rather than a detailed technical writeup, defenders should await further reporting for IOCs, TTPs, or confirmed attack chain details. Organizations with third-party relationships to Onsemi should assess potential downstream exposure given the reported third-party credential compromise.

Mentioned in this report

Threat actors qilin
Malware Qilin

Source reporting: https://www.ransomware.live/id/T25zZW1pQHFpbGlu

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,745 reports from 152 sources, 487 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs