ATT&CKReferencesBushidoToken Qilin RaaS JUN 2024

BushidoToken Qilin RaaS JUN 2024

Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareQilin

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1484.001
Group Policy Modification
MalwareQilin

Qilin has pushed a scheduled task via a Group Policy Object for payload execution.

T1486
Data Encrypted for Impact
GroupWater Galura

Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1585.001
Social Media Accounts
GroupWater Galura

Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS.

T1657
Financial Theft
GroupWater Galura

Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site.

T1688
Safe Mode Boot
MalwareQilin

Qilin can reboot targeted systems in safe mode to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.