~/f4n6 $ grep -r "Ransomware: qilin named Hoc (GB)" ./investigations/ --include="*.md"

Ransomware: qilin named Hoc (GB)

Jeff Davies 29 Jul 2026 3 min read

1. Executive summary

On 28 July 2026, the Qilin ransomware group publicly claimed a victim named "Hoc" (domain: www.hocltd.com), a UK-based organisation. The claim was posted on the group's leak site and indexed by Ransomware.live. Attribution to the Qilin group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests on a single source (Ransomware.live). The victim appears in a cluster of at least six Qilin claims across the UK, Belgium, Germany, and Italy in the same period, suggesting an active campaign. No technical details of the intrusion, initial access vector, or malware payload are available in the source material.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The source material contains only a public ransomware claim with no confirmed intrusion details, no confirmed impact on the named victim's operations, and no indication that the victim is a regulated EMEA financial-services entity. Generic incident-management obligations that would apply to any security incident are not distinctive triggers and are excluded per the advisory test.

3. Technical analysis & attack chain

No technical attack-chain detail is available in the source material. The primary item and related sources contain only victim-claim metadata (group name, victim name, country, website domain) published via Ransomware.live.

What is confirmed (single-sourced; verify before enforcement)

  1. Public claim: The Qilin ransomware group posted "Hoc" (www.hocltd.com, GB) as a victim on or before 28 July 2026.
  2. Hudson Rock enrichment: Ransomware.live's Hudson Rock-sponsored enrichment panel reports 1 compromised user and 2 external-attack-surface entries associated with the victim's domain. No compromised employees or third-party employee credentials are listed. This data is single-sourced and has not been independently corroborated.
  3. Campaign context: Qilin has claimed at least five additional victims in the same timeframe — GOP (GB, www.gopltd.com), TQ Financial Services (www.tqfinancials.com), Bristol Place (GB, www.bristolplace.net), Sintax (BE, www.sintax.be), dbHMS (DE, www.dbhms.com), and Sicc (IT, www.sicc-srl.com). The TQ Financial Services claim is notable for EMEA financial-services clients as it names a financial-services entity directly, though no country was specified.

What is NOT available

  • Initial access vector
  • Exploited CVE or component
  • Malware payload, variant, or capabilities
  • Persistence mechanism
  • Privilege escalation technique
  • C2 infrastructure
  • Lateral movement detail
  • Data exfiltration volume or file lists
  • Ransom note content
  • Encryption mechanism

Attribution caveat: "Qilin" has no MITRE ATT&CK profile in the verified reference data. Attribution rests solely on the Ransomware.live listing. Treat as unconfirmed.

4. Mitigation & containment

No technical containment or remediation actions can be specified from the source material — there are no CVEs, no malware hashes, no C2 indicators, and no documented initial-access vector to act upon.

P1 — within 24h

  • If your organisation has a business or supply-chain relationship with Hoc (www.hocltd.com) or any of the named co-victims (GOP, TQ Financial Services, Bristol Place, Sintax, dbHMS, Sicc), assess exposure: identify data shared, integrations, VPN or trust relationships, and third-party credentials stored. Suspend non-essential connectivity pending confirmation of the breach scope.
  • Review the Hudson Rock report of 1 compromised user associated with www.hocltd.com — if your organisation holds credentials for that user or domain, force password rotation and revoke active sessions.

P2 — within 72h

  • Threat-hunt for Qilin TTPs using your own threat-intelligence sources. The verified reference data provides no MITRE ATT&CK techniques for this actor, so use internally curated or commercial threat-intel profiles for Qilin with appropriate confidence caveats.
  • If supply-chain exposure to any named victim is confirmed, document the assessment per your ICT third-party risk process.

P3 — within 7 days

  • Monitor Ransomware.live and the Qilin leak site for additional claims targeting EMEA financial-services entities. The TQ Financial Services claim warrants particular attention.
  • Review external attack surface for the 2 entries flagged by Hudson Rock if you are the affected organisation.

5. Indicators of compromise

No indicators of compromise available in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
1 compromised user associated with victim domain (www.hocltd.com) Hudson Rock / infostealer intelligence platform Low — single-sourced, uncorroborated
2 external attack surface entries for victim domain External attack surface management tool Low — single-sourced, uncorroborated

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Ransomware: qilin named Hoc (GB)," https://www.ransomware.live/id/SG9jQHFpbGlu, published 2026-07-28
  • Ransomware.live, "Ransomware: qilin named GOP (GB)," https://www.ransomware.live/id/R09QQHFpbGlu
  • Ransomware.live, "Ransomware: qilin named TQ Financial Services," https://www.ransomware.live/id/VFEgRmluYW5jaWFsIFNlcnZpY2VzQHFpbGlu
  • Ransomware.live, "Ransomware: qilin named Bristol Place (GB)," https://www.ransomware.live/id/QnJpc3RvbCBQbGFjZUBxaWxpbg==
  • Ransomware.live, "Ransomware: qilin named Sintax (BE)," https://www.ransomware.live/id/U2ludGF4QHFpbGlu
  • Ransomware.live, "Ransomware: qilin named dbHMS (DE)," https://www.ransomware.live/id/ZGJITVNAcWlsaW4=
  • Ransomware.live, "Ransomware: qilin named Sicc (IT)," https://www.ransomware.live/id/U2ljY0BxaWxpbg==

8. Adverse Trace position

This is a low-fidelity, single-sourced ransomware claim with no technical detail available for defensive action. The Qilin attribution is unconfirmed (no MITRE ATT&CK profile in verified reference data). The immediate risk to EMEA financial-services clients is supply-chain exposure if they have relationships with Hoc or the co-victims — particularly TQ Financial Services. We assess this as a watch-and-monitor item: clients should complete the P1 third-party exposure check and continue tracking the Qilin campaign cluster. Adverse Trace will update this advisory if technical details, IOCs, or confirmed intrusion reporting emerge.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies