Skip to content

RingQ

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

2 named in public reporting
Larva-26009

RingQ is a tool available on GitHub that reads an encrypted file located in the same Path, decrypts it, and executes it in memory.

Shadow-Earth-053

In one targeted environment, we detected a sample of RingQ, which is an open-source tool of Chinese origin available on GitHub that is designed to pack malicious binaries in order to evade detection by security solutions.

MITRE ATT&CK

RingQ in ATT&CK

6 distinct techniques

Reporting

Research mentioning RingQ