ATT&CKReferencesSophos Qilin MSP APR 2025

Sophos Qilin MSP APR 2025

Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareQilin

Qilin can enumerate domain-connected hosts during its discovery phase.

T1070.004
File Deletion
MalwareQilin

Qilin can delete itself from infected hosts after execution.

T1204.001
Malicious Link
MalwareQilin

Qilin has been executed by luring victims into clicking links in spearphishing emails.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1566.002
Spearphishing Link
MalwareQilin

Qilin has been delivered via malicious links in spearphishing emails.

T1685.005
Clear Windows Event Logs
MalwareQilin

Qilin has the ability to clear Windows Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.